Back to skill

Security audit

Namecheap Dns Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill is a DNS management helper, but it combines live Namecheap DNS mutation authority with overly broad activation text and limited safety guidance.

Review this before installing if you use production domains. Only invoke it for explicit Namecheap DNS tasks, protect the API key, and back up current DNS records before any update, delete, or nameserver change. The artifact should narrow its activation language and add confirmation and rollback guidance before routine use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill advertises very broad activation language such as general coding, debugging, testing, and deployment use, even though its real function is DNS administration. In an agent ecosystem, this can cause the skill to be invoked in unrelated contexts and increase the chance of sensitive DNS operations being surfaced or executed when the user did not specifically request domain changes.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The coverage keywords include fragmented and vague trigger terms like 'Use', 'when', '代码生成', '编程辅助', and other broad phrases unrelated to DNS management. This increases the chance of opportunistic or accidental skill selection, which is risky because the skill exposes destructive infrastructure actions such as record modification and deletion.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation includes a destructive DNS delete command without any warning, confirmation requirement, rollback guidance, or emphasis on service impact. In context, DNS deletion can immediately break website routing, email delivery, domain validation, and other production services, so normalizing the command without safeguards materially increases operational risk.

Missing User Warnings

Low
Confidence
76% confidence
Finding
The skill instructs users to export and set live API credentials in environment variables but does not warn against logging, echoing, committing, or sharing those secrets. In an agent-driven environment with read/exec tools, poor secret-handling guidance can lead to accidental credential disclosure and unauthorized DNS changes.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.