Back to skill

Security audit

管理和控制

Security checks across malware telemetry and agentic risk

Overview

This skill is a macOS system-control helper, but it asks for broad command authority with unclear boundaries and contradictory platform guidance.

Review carefully before installing. This skill may be useful for deliberate macOS administration, but only use it when you explicitly want local system-control actions, and confirm any action that could terminate processes, change network or power settings, capture the screen or clipboard, or modify files. Do not rely on its sandbox claim unless the host agent independently enforces sandboxing and command approvals.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill claims commands run in a 'safe sandbox', but the file only exposes generic exec capability and provides no technical mechanism enforcing isolation, command restrictions, or containment. This can mislead users and downstream agents into trusting dangerous system-control actions under a false assumption of safety.

Intent-Code Divergence

Medium
Confidence
81% confidence
Finding
The skill is positioned as controlling macOS system functions, yet the runtime section claims Windows and Linux support. This mismatch can cause the skill to be invoked in unintended environments where commands may fail unpredictably or map to different privileged operations, increasing the chance of unsafe execution behavior.

Intent-Code Divergence

Medium
Confidence
80% confidence
Finding
A repeated claim of Windows/Linux compatibility contradicts the macOS-specific purpose of the skill, reinforcing ambiguous activation and execution context. In a skill with exec and system-control semantics, platform ambiguity increases the risk of accidental misuse or unsafe command translation by an agent.

Vague Triggers

High
Confidence
89% confidence
Finding
The activation guidance is broad and overlaps with common efficiency, automation, and workflow requests, which can cause an agent to select this powerful system-control skill for benign-looking prompts. Because the skill has read, write, and exec capabilities and can manage processes, network, power, screenshots, clipboard, and Finder operations, overbroad routing materially raises the chance of unauthorized or destructive actions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill describes sensitive system-control functions such as process management, network management, power management, screenshots, clipboard access, and Finder operations without prominent warnings about destructive, privacy-impacting, or privileged behavior. In this context, missing warnings and approval boundaries make accidental harmful execution more likely and reduce informed user consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.