Back to skill

Security audit

Node Connect Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a real local network troubleshooting guide, but it needs Review because it can change pairing trust and configuration without clear user confirmation or tight scope.

Install only if you are comfortable letting an agent run local skill-platform commands and potentially change gateway configuration or approve a pending device. Treat it as diagnostic-plus-remediation, not read-only troubleshooting, and require confirmation before any approve, write, restart, or configuration change.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The documentation claims the tool only provides diagnosis and suggestions, yet elsewhere it instructs the agent to perform state-changing actions such as approving devices. That mismatch can mislead users and downstream agents into granting permissions or modifying system state without informed consent, increasing the risk of unintended trust decisions during pairing.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
A free edition described as diagnosis-focused should not silently expand into operational actions like approval or modification. This broadening of capability creates a trust-boundary problem: users may invoke what they believe is a read-only troubleshooting skill, while the agent is actually authorized to perform changes affecting connectivity and device trust.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The manifest and description present a narrowly scoped local/LAN diagnostic tool, but the body advertises generic create/modify/delete/import/export operations via abstract parameters. In an agent environment with write and exec tools, this overbroad operational language can be interpreted as permission to perform unrelated or destructive actions beyond diagnosis, increasing the attack surface from documentation ambiguity alone.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger conditions are written so broadly that the skill may activate for generic development, debugging, or deployment requests outside its intended narrow network-diagnosis use case. In a tool-enabled agent, over-triggering can cause unnecessary command execution or irrelevant guidance in contexts where the user did not intend to authorize this skill.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill describes modifying configuration, saving output, and executing commands but does not provide clear safety warnings, rollback guidance, or consent requirements. In an environment with exec/write enabled, users may not understand that running the skill could alter local configuration or pairing state, leading to accidental disruption or trust changes.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.