Back to skill

Security audit

多代理开发

Security checks across malware telemetry and agentic risk

Overview

This is a mostly coherent multi-agent coding workflow, but it mixes high-impact write/command/subagent authority with unrelated and contradictory API, credential, and generic automation instructions.

Review this skill before installing. It is not malicious from the inspected artifact, but users should treat it as a Review item because it can guide agents to modify code, run commands, coordinate subagents, and possibly use credentials or external services despite unclear and contradictory documentation. Only use it in a scoped repository/worktree with an approved plan, and do not allow API-key use or external calls unless you explicitly intend them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill presents itself as pure Markdown guidance with no extra API-key needs, but later instructs users to configure API keys, call external services, and run network diagnostics. This kind of contradictory documentation can mislead an agent or operator into enabling networked or credentialed behavior they did not intend, weakening trust boundaries and informed consent.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The file claims to be a specific multi-agent development workflow, but large autogenerated sections describe generic CRUD-style processing and structured outputs unrelated to the actual skill. This ambiguity expands the apparent authority of the skill and can cause an agent to perform actions outside the intended workflow based on misleading capability claims.

Vague Triggers

High
Confidence
94% confidence
Finding
The activation guidance is extremely broad, covering common coding, debugging, testing, and deployment requests. In a skill with read/exec/write tools and multi-agent orchestration, overbroad triggering increases the chance the skill is invoked in situations where users did not intend expansive automation, code changes, or command execution.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill describes file writes, command execution, and API/external operations as normal capabilities without prominent user-facing warnings or consent checkpoints. This can normalize high-impact actions and lead agents to perform modifications, execute shell commands, or contact external services without adequately surfacing risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.