Back to skill

Security audit

多源研究助手

Security checks across malware telemetry and agentic risk

Overview

This research skill does not show malicious behavior, but it asks for command execution and broad file/API handling without clear limits.

Install only if you are comfortable with a research helper that may run shell commands and process local files. Keep it restricted to low-risk workspaces, avoid giving it sensitive files or credentials unless necessary, and review any command or file-write action before allowing it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill presents itself as a research aggregation assistant, but the documented capabilities include command execution and file handling that are broader than necessary for the stated purpose. This creates an unnecessary expansion of the attack surface: an agent may invoke shell commands or manipulate local data based on loosely scoped instructions, increasing the risk of misuse, prompt injection follow-on actions, or unintended system interaction.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
Later sections describe generic API setup, file processing, and command execution workflows that are not tightly tied to multi-source research. This kind of scope drift can cause an agent to treat the skill as a general-purpose execution wrapper, making it easier for untrusted content or user prompts to route into unrelated high-risk actions.

Vague Triggers

Medium
Confidence
76% confidence
Finding
The activation guidance is broad enough to match many generic research or information-gathering requests, which increases the chance the skill is auto-selected in situations beyond its safe scope. Over-broad routing is dangerous here because the skill also advertises elevated capabilities, so accidental invocation could expose command execution or other unnecessary tooling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.