Back to skill

Security audit

Memory Radar

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed memory-file security scanner with optional remote analysis and reversible quarantine, though its scope text is somewhat broad and the referenced scripts are not included in the artifact.

Before installing, treat this as a local memory security tool that may read sensitive memory/config files and may modify them only after confirmation. Prefer local mode first, review any referenced scripts or generated implementation before running them, and enable remote LLM analysis or scheduled scans only if you are comfortable with the disclosed data handling and persistence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill includes broad, generic operational language like '解析用户指令,执行核心操作并返回处理结果' without tightly constraining invocation to explicit security-scan intents. In an agent environment with exec capability, vague trigger text can cause the skill to activate for unrelated requests and perform unintended command execution or file-modifying workflows, increasing the chance of unsafe actions under ambiguous prompts.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The additional generic capability descriptions and broad '能力覆盖范围' materially widen the trigger surface beyond a narrowly defined memory-security scanner. In the context of a skill that declares the exec tool, overbroad capability text can make the agent match this skill to unrelated tasks, creating a prompt-routing and unintended-action risk that is more dangerous here than in a read-only documentation skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.