Back to skill

Security audit

API自动生成工具

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a magic-api helper, but it asks for broad read/write/command authority and has vague activation guidance for a tool that can generate HTTP and database-facing behavior.

Review before installing. Use this only for explicit magic-api development work, avoid giving it broad credentials, and require user confirmation before command execution, database changes, file writes, or publishing generated scripts as reachable HTTP endpoints.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill is presented as an API generation helper, but it also advertises generic file handling, external API access, information retrieval, and especially command execution. That materially expands its capability beyond the stated purpose and can enable an agent to run system commands or manipulate local resources under the guise of a normal development request.

Vague Triggers

High
Confidence
92% confidence
Finding
The activation text is overly broad, including generic productivity and automation phrases that can match many unrelated user requests. In an agent ecosystem, this increases the chance the skill is invoked in contexts where its powerful capabilities—such as script generation, file access, or execution—are unnecessary and potentially unsafe.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The guidance around use and non-use is vague and does not clearly separate eligible requests from ineligible ones. This ambiguity can cause unintended activation and overreach, especially when combined with tools that can read, write, and execute.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The description emphasizes convenience and automation but does not clearly warn that generated scripts can be exposed directly as HTTP endpoints and may impact data integrity, authentication surfaces, or system behavior. This omission can mislead users and agents into treating the skill as low-risk when it can create network-reachable functionality with meaningful security implications.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.