Back to skill

Security audit

新闻

Security checks across malware telemetry and agentic risk

Overview

This market-news skill is not clearly malicious, but it asks for command execution and broad file/API capabilities that are wider than its news-summary purpose explains.

Review this skill before installing. It may be suitable only if you are comfortable granting a news-summary skill command execution authority and broad routing language; otherwise prefer a version limited to market-news search and summarization with no exec tool and clearer data-handling claims.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill is presented as a market-news search/summarization tool, but its manifest and documentation expand its capabilities to generic file handling, API access, and system command execution. This scope expansion is dangerous because it can cause the agent to invoke the skill in contexts far beyond news analysis, increasing the chance of unintended file access or shell execution under a misleading, low-risk label.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
A financial news tool does not inherently require shell command execution, so exposing or advertising exec capability creates unnecessary attack surface. If the agent routes broad user instructions to this skill, attackers may leverage the unjustified execution primitive to run local commands, access files, or pivot into the host environment.

Intent-Code Divergence

Medium
Confidence
79% confidence
Finding
The documentation claims encrypted transmission and storage without describing any actual storage behavior, controls, or implementation details. Misleading security assurances are dangerous because users or orchestrators may trust the skill with sensitive data under false assumptions, resulting in inappropriate data exposure or weak operational decisions.

Vague Triggers

High
Confidence
94% confidence
Finding
The activation guidance is so broad that the skill may be selected for generic efficiency, automation, or workflow tasks unrelated to market news. In combination with the declared read/exec capabilities, this broad routing language materially increases the likelihood that the skill is invoked in higher-risk contexts where it can access files or execute commands unnecessarily.

Vague Triggers

High
Confidence
92% confidence
Finding
The additional 'Use when' wording is vague and broad enough to capture common analytics and workflow scenarios outside the skill's stated purpose. This weak scoping makes misrouting more likely, and because the skill advertises sensitive capabilities, misuse could lead to over-privileged actions under the guise of a harmless news tool.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.