Back to skill

Security audit

Ops Dashboard Free

Security checks across malware telemetry and agentic risk

Overview

This skill is an operations monitoring helper, but its read-only claims conflict with write-capable metadata and modification-oriented instructions.

Review carefully before installing. Use it only for explicit, local, read-only dashboard checks, and avoid granting write authority unless the publisher clarifies the conflicting create/modify/import/reset/save instructions. Treat session, cron, config, and environment-check output as sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill repeatedly claims the free edition is read-only and does not support change operations, yet the parameter sections advertise create/modify/import/export/reset/save actions. This mismatch can mislead an agent or user into attempting state-changing behavior under a supposedly safe monitoring skill, weakening trust boundaries and increasing the chance of unintended configuration or data changes.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The documentation says change operations are unsupported, but later sections describe modification-oriented actions via config_options and output handling. In an agent-driven environment, contradictory instructions are dangerous because the model may follow the more permissive path and perform writes, imports, or resets despite the advertised safety posture.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The activation guidance is broad enough to match generic system monitoring, log analysis, alerting, and deployment-management requests. Overbroad routing increases the chance this skill is invoked in contexts involving sensitive operational data or actions outside its safe scope, especially since it also exposes exec and network-driven examples.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The keyword coverage section is excessively expansive and includes many generic operational terms, making accidental or opportunistic activation far more likely. In an agent ecosystem, broad trigger surfaces can cause the skill to run during unrelated tasks and initiate local API queries or sensitive environment/config inspection without sufficiently specific user intent.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill description does not clearly warn that its examples perform live HTTP requests to local services and may access sessions, config, environment-derived values, and other operationally sensitive data. Without an upfront warning, an agent or user may treat the examples as harmless documentation and expose internal status or secrets-adjacent information during routine use.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.