Back to skill

Security audit

Knowledge Capture Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill matches a knowledge-capture purpose, but it asks for broad write and command-execution authority while leaving deletion, storage location, and user confirmation poorly scoped.

Install only if you are comfortable granting this skill write access and possible shell-command use. Before using it with sensitive conversations or meeting notes, decide where outputs may be saved and require explicit confirmation before any modify/delete operation or command execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill is presented as a simple personal knowledge-capture tool, but it explicitly declares and documents `exec` support, which can enable arbitrary command execution far beyond the advertised feature set. In an agent environment, this materially increases the attack surface because user-provided content or loosely specified workflows could be translated into shell commands with filesystem or network effects.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The documented capability scope includes create/query/modify/delete operations even though the skill is described as a basic free knowledge-capture and archiving tool. This mismatch can mislead users and agents into granting broader authority than expected, increasing the risk of unauthorized modification or deletion of notes, documents, or knowledge-base content.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The description says extracted knowledge is automatically saved to a knowledge base or document system without warning the user that their conversation data may be written or persisted. Because the skill handles potentially sensitive meeting notes and personal discussions, silent storage creates privacy and data-governance risk.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The capability text includes create/modify/delete-style operations without warning that these actions can change or remove stored knowledge. Users may invoke the skill expecting passive analysis, while the skill may perform mutating operations that alter documents or records, causing integrity loss.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.