Back to skill

Security audit

Model Routing Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a model-routing guide, but it asks for command execution and describes broad create/delete/export/save behavior that is not clearly scoped to that purpose.

Review this skill before installing. It may be useful as a routing reference, but only enable command execution or file-changing actions if you actually need them and can constrain them. Avoid using it for sensitive prompts, credentials, or automatic agent dispatch unless you have explicit controls around provider data sharing and command execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The skill is presented as a narrow model-routing guide, but the body introduces generic create/query/modify/delete/export/save/convert style operations that materially expand its apparent authority. This mismatch can mislead users and host agents into granting or invoking capabilities beyond the declared purpose, increasing the chance of unsafe execution paths or policy bypass through ambiguous documentation.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
A free routing-focused skill claiming file-writing, save, or export capabilities creates a deceptive capability boundary. Even if not malicious, this can cause users or orchestrators to treat the skill as authorized for data-changing actions, which raises the risk of unintended persistence or exfiltration workflows.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The documentation introduces broad execution-oriented functions unrelated to a model-routing advisor, blurring the line between recommendation logic and action execution. In a skill with exec listed in tools, such overbroad capability claims make unsafe invocation more likely because users may infer the skill can legitimately perform arbitrary operational tasks.

Vague Triggers

Medium
Confidence
86% confidence
Finding
Automatic activation on broad keywords like model routing, cost optimization, agent dispatching, or scheduled-task model selection can trigger unintentionally during ordinary conversation. Overbroad activation increases the chance that the skill influences unrelated requests, causing misrouting, unnecessary tool exposure, or user confusion about when the skill is in control.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The stated trigger condition covers very broad classes of AI use, orchestration, and LLM applications, making the skill prone to activating in contexts far beyond its narrow purpose. In practice, this broadness can let a routing guide intercept unrelated workflows and shape model/tool decisions without sufficient user awareness.

Missing User Warnings

Medium
Confidence
81% confidence
Finding
The skill advertises exec-backed functionality without warning users about command execution risks, side effects, or environment impact. Because exec can affect the local system, missing disclosure and guardrails can lead users to invoke the skill without understanding that shell commands may run or that outputs may depend on host context.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill discusses provider API usage and API keys but does not warn that prompts, files, or metadata may be sent to third-party model providers. This omission can cause users to unknowingly transmit sensitive data outside the local environment, especially in a tool framed as a simple Markdown routing guide.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.