Back to skill

Security audit

社区垃圾过滤

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a spam-filtering helper, but it asks for command/write capability and credential access while its scope and data-flow documentation are inconsistent.

Review before installing. Use it only in a sandboxed workspace for the specific community-feed filtering task, avoid granting broad shell/write access, prefer environment variables or managed secrets over raw credential files, and do not use callback URLs unless you are comfortable with what data may be sent there.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The skill claims it is read-only, does not modify content, and does not send data to third parties, yet elsewhere it supports callback URLs, external API usage, and network/API integration. This kind of contradictory documentation can mislead users and agents into granting trust or permissions under false assumptions, increasing the chance of unintended data disclosure or network exfiltration.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The document presents the skill as Markdown-only and natural-language driven, but elsewhere advertises exec support and an MD+EXEC classification. This mismatch can cause users or automated platforms to treat the skill as lower risk than it is, despite it being capable of running shell commands.

Vague Triggers

High
Confidence
88% confidence
Finding
The activation language is extremely broad, framing the skill as suitable for generic productivity, automation, workflow optimization, and batch processing. Overbroad triggering increases the chance that an agent invokes a skill with exec/write/network-adjacent capabilities in unrelated contexts where the user did not intend to authorize such behavior.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises command execution capability without a clear, prominent warning to the user. When a skill can invoke shell commands, omission of an upfront warning undermines informed consent and increases the risk of unsafe execution in environments containing sensitive files, tokens, or network access.

Credential Access

High
Category
Privilege Escalation
Content
- 垃圾去除率:96%
- 误判率:<1%(多为合法提及铸造的边界情况)
- 处理速度:100帖约10ms
- 凭证读取:`~/.config/platform/credentials.json`

## 应用场景
| 场景 | 输入 | 输出 |
Confidence
97% confidence
Finding
credentials.json

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.