Back to skill

Security audit

Key Vault Manager

Security checks across malware telemetry and agentic risk

Overview

This skill is framed as a key vault manager but asks for broad local authority and mixes in unrelated security-audit behavior without clear limits.

Review this skill carefully before installing. It may handle API keys, local configuration files, audit logs, and command execution, but its stated scope is inconsistent and its write/exec/logging behavior is not bounded enough. Only use it in a controlled workspace with explicit file backups and do not give it access to unrelated secrets or repositories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The skill’s documented inputs, outputs, and examples switch from key-vault management to code/security auditing behavior, creating a strong mismatch between declared purpose and actual described function. This can cause an agent or user to invoke the skill in unintended contexts, increasing the risk of overbroad data access, misleading execution, and unsafe use of read/write/exec capabilities under false expectations.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The professional feature list advertises vulnerability scanning, CVE correlation, threat intelligence, and zero-day detection even though the rest of the skill is framed as a key vault manager. This kind of capability inflation is dangerous because it obscures the true operational scope and may justify unnecessary privilege or user trust for actions unrelated to secure key storage.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The manifest-level description blends key-vault management with security detection, compliance auditing, and vulnerability scanning, making the skill’s purpose ambiguous. Ambiguous scope weakens user consent and policy enforcement because an agent may route tasks or expose sensitive data to a skill whose real behavior is unclear.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The skill declares exec capability even though the documented purpose does not justify unrestricted system command execution. When combined with key-handling and file access, unnecessary exec materially raises the blast radius, enabling command execution against local systems under the guise of vault operations.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation text uses broad trigger language such as security detection, compliance audit, and vulnerability scanning without precise invocation boundaries. Broad matching can cause accidental activation on unrelated sensitive tasks, exposing content or enabling privileged actions when the user did not specifically request this skill.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The document states that key rotation can automatically synchronize new keys into all configuration files using the key, but it does not provide a clear warning or confirmation requirement before modifying user data. Silent or implicit file modification is risky because it can corrupt configs, change deployment behavior, or propagate secrets into unintended locations.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill claims full audit logging of key operations and file reads, including detailed metadata, without a clear privacy notice or data-retention warning. Because key-management workflows inherently involve sensitive identifiers and access patterns, undisclosed activity logging can create secondary exposure of confidential operational data.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.