Back to skill

Security audit

Multi Source Research Tool Free

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward research-assistant skill that uses web and source gathering in ways that match its stated purpose, with privacy and trigger-scope caveats users should understand.

Install only if you are comfortable with an agent using internet search and source scraping for your research topics. Avoid putting confidential project names, personal data, or sensitive internal questions into prompts unless you explicitly want those terms sent to external sources. Consider narrowing when the skill should activate so it does not handle unrelated analysis tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger examples use very common natural-language phrasing such as '帮我研究…', which overlaps heavily with ordinary user requests. This can cause the skill to activate unexpectedly for broad research-related prompts, expanding its access to networked data gathering and tool usage without clear user intent to invoke this specific skill.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The stated trigger condition says the skill should be used whenever data analysis, reporting, statistics, or visualization are needed, which is far broader than the actual scope of a multi-source research assistant. Such ambiguous activation criteria can make the skill intercept unrelated tasks, leading to overbroad invocation and unnecessary external searches or processing.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises collecting information from web search, academic platforms, social media, and news sources, but it does not prominently warn users that their queries may be transmitted to third-party services. This creates a privacy risk because sensitive research topics, internal project names, or personal data could be exposed externally without informed consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.