Back to skill

Security audit

笔记

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a note helper, but it requests command execution and broad file/API capabilities without clear limits and includes mismatched instructions.

Review before installing. This skill may be harmless boilerplate, but it asks for command execution and broad local search/read capabilities while giving unclear and partly unrelated instructions. Only install it if you are comfortable granting those tools, or revise it to remove exec, define exact note workflows, and scope file/API access clearly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill documentation gives contradictory availability classifications, describing the skill once as 'MD+execute()' and later as pure Markdown. In an agent ecosystem, this ambiguity can cause the runtime or operator to assume command execution is permitted when reviewing a seemingly harmless note skill, increasing the chance of unsafe tool exposure and misuse.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The documented request/response format describes a scoring and compliance-evaluation output unrelated to note capture, linking, or retrieval. This mismatch can mislead agents into sending inappropriate data, trusting fabricated evaluation fields, or invoking the skill in the wrong workflows, which is dangerous when combined with broad tool permissions.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill claims file handling, external API integration, and system command execution far beyond the stated note-capture purpose. In context, this is especially risky because a productivity/note skill is likely to be invoked with user content and broad trust, so overclaimed capabilities can become a path to command execution, data exfiltration, or unintended system interaction.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger description is incomplete and ambiguous ('Use when user...'), so the skill lacks clear invocation boundaries. In agent routing systems, vague triggers can cause the skill to be selected in unrelated tasks, exposing unnecessary tools and broadening the attack surface through accidental invocation.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The feature list repeats a vague usage condition without scope constraints, leaving the skill's intended operating boundary unclear. Because the skill also advertises API and execution-related behavior, this ambiguity makes accidental overuse more dangerous by encouraging invocation in broader integration scenarios than a note skill should handle.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.