Back to skill

Security audit

产物验证门禁

Security checks across malware telemetry and agentic risk

Overview

This skill is a Markdown-only security gate that asks for broad tool authority and advertises protections it does not actually define or implement.

Treat this as a Review item before installing. It does not show malicious code, exfiltration, or destructive behavior, but users should not rely on its advertised blocking, ML, API authentication, or policy synchronization claims unless the publisher adds concrete implementation details and clear limits for write, exec, API key, and file access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The skill documentation claims API-key-authenticated external API behavior and policy synchronization despite containing only Markdown instructions with no implementation. This is dangerous because users or agents may assume security controls, remote validation, or authenticated safeguards exist when they do not, leading to misplaced trust and insecure deployment decisions.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The FAQ asserts machine-learning detection, automatic blocking, and security-database synchronization without any corresponding implementation. Such overstated security functionality can cause operators to rely on nonexistent protections, allowing unsafe artifacts to pass through a process believed to be enforced.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The feature list advertises file handling, API integration, and sandboxed command execution, but the skill content does not define operational logic for those actions. In an agent ecosystem, this mismatch can mislead users into granting trust or permissions on the assumption that controlled, purpose-built behavior exists when it does not.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The invocation guidance is very broad, encouraging use across AI model calls, agent orchestration, and LLM applications without specific trigger conditions or scope limits. Overbroad activation criteria increase the chance the skill will be invoked in inappropriate contexts, where users may overestimate its safety-review function or allow it to influence sensitive workflows without defined boundaries.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill advertises read, write, exec, and API-related capabilities without user-facing warnings about their impact, despite presenting itself as a security-related gate. In context, this is more dangerous because users may trust a 'security' skill more readily and overlook the operational risk of granting it file modification, command execution, or network-oriented authority.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.