Back to skill

Security audit

类型化知识图谱引擎

Security checks across malware telemetry and agentic risk

Overview

The skill is not overtly malicious, but its broad read/exec authority and generic API, file, and command automation claims go beyond the stated local knowledge-graph memory purpose.

Review this skill before installing. It appears intended for local structured memory, but only use it if you are comfortable with an agent reading files and running shell commands, and constrain usage to the memory/ontology workflow rather than generic API calls or arbitrary command execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented as a local typed knowledge-graph memory system, but later expands its claimed capabilities to generic file processing, API integration, and command execution. This scope drift can cause an agent or reviewer to authorize broader behavior than users expect, increasing the chance of unsafe tool use under a misleading trust boundary.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Advertising external API integration for a skill whose stated purpose is local ontology-backed memory unnecessarily broadens the operational scope. In an agent environment, this can prompt outbound data transmission or secret use that users would not reasonably expect from a local memory skill.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Generic command execution is materially more dangerous than the stated graph-memory purpose requires, especially because the skill already requests the exec tool. This creates a path for unintended shell activity, filesystem modification, or abuse of user-supplied input under the cover of a benign-seeming memory skill.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger description is overly broad, covering general AI calling, chat, agent orchestration, and LLM apps. Overbroad activation criteria can cause the skill to be invoked in unrelated contexts, where its exec/read permissions and memory-manipulation behavior may be inappropriate or risky.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.