Back to skill

Security audit

Namecheap DNS工具

Security checks across malware telemetry and agentic risk

Overview

This skill is mainly for Namecheap DNS changes, but its instructions mix in unrelated uses and unsupported security claims around a high-impact DNS mutation workflow.

Review this skill carefully before installing. Use it only for explicit Namecheap DNS work, verify every planned DNS change with dry-run/diff output, keep backups, and do not rely on its unrelated project-management or security-scanning claims.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The manifest description mixes DNS-management behavior with unrelated project-management and team-collaboration claims, which can cause an agent or user to invoke the skill in inappropriate contexts. In a tool that has read/exec/write capabilities, ambiguous scope increases the chance of unintended execution paths, misuse of credentials, or operator confusion about what actions the skill will perform.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The documented result format describes scoring, grading, and audit-style output that is unrelated to DNS record management, indicating the skill content may be copied from another domain. This mismatch can mislead downstream automation into trusting incorrect output schemas, causing unsafe parsing, skipped validation, or execution based on fabricated success semantics.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
Advertising vulnerability scanning, compliance auditing, asset risk scoring, and threat intelligence in a DNS-management skill materially overstates the skill's security authority. This can lead users or autonomous agents to rely on the skill for security decisions it cannot actually support, creating dangerous false assurance in a context that already permits DNS changes and command execution.

Vague Triggers

High
Confidence
97% confidence
Finding
Overly broad and ambiguous invocation text unrelated to DNS management can cause the skill to trigger for many unrelated requests. Because the skill declares read, write, and exec tools and operates on destructive DNS APIs, an overly permissive activation scope increases the chance of accidental or unauthorized use in contexts where DNS modification was never intended.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The markdown does not provide clear trigger phrases, decision rules, or strong exclusion conditions, so an agent may apply the skill based on weak semantic overlap. In a destructive infrastructure-management context, underspecified activation logic increases the risk of the wrong skill being selected and performing sensitive operations on DNS state.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
Mandating Chinese interaction without clear user opt-in can cause misunderstanding of safety prompts, confirmations, and destructive-operation warnings for users who did not request that language. In a DNS-management skill, any reduction in user comprehension around verify/force/rollback flows raises operational risk, even if it is not a classic code-execution flaw.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.