Back to skill

Security audit

Model Switching Tool Free

Security checks across malware telemetry and agentic risk

Overview

This model-selection guide is mostly instructional, but it asks for write and command-execution authority that is broader than its stated purpose.

Review before installing. The core guidance may be useful for choosing cheaper Claude model tiers, but grant it only in an environment where broad file writes and command execution are acceptable, or require the publisher to remove or tightly scope those capabilities first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is advertised as a narrow model-selection guide, but the body expands into generic create/modify/delete/export/save operations. This scope inflation can cause an agent to perform actions beyond user expectations, increasing the risk of unsafe file or workflow manipulation under the guise of benign guidance.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The free version claims to focus on decision guidance, yet the manifest grants write and exec capabilities. That mismatch is dangerous because an agent may be authorized to alter files or run commands even though users would reasonably expect a read-only recommendation tool.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
Executable-command capability is not justified by the stated purpose of providing model-switching guidance. Unnecessary exec access materially raises the attack surface because any prompt confusion, misuse, or hidden instruction path could lead to command execution on the host environment.

Context-Inappropriate Capability

Low
Confidence
88% confidence
Finding
The documentation introduces import/reset/save/export behaviors unrelated to a simple model-selection guide. These generic operational verbs can be interpreted by an agent as permission to mutate state or persist data, broadening the skill from advice into action without adequate justification or safety framing.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Automatic activation based on broad everyday keywords makes the invocation boundary vague and over-inclusive. That can trigger the skill in unrelated contexts, especially dangerous here because the skill also declares write and exec capabilities that could be brought into scope unexpectedly.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger condition states the skill should be used for broad AI/agent/LLM scenarios, which is far wider than its advertised purpose. Overbroad routing increases the chance that unrelated tasks get handled under this skill's permissions, enabling unintended writes or command execution.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill describes write/modify/delete and exec-backed operations without clear warnings about system impact or consent requirements. In a skill with operational permissions, omission of user-facing safety boundaries can lead to destructive changes or command execution without informed approval.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.