Back to skill

Security audit

Pan File Commander Free

Security checks across malware telemetry and agentic risk

Overview

This Baidu Netdisk skill should be reviewed before use because unrelated SEO trigger text could invoke it outside file-management tasks, and it can run shell commands that modify or publicly share cloud files.

Install only if you specifically want an agent to manage Baidu Netdisk files through bdpan. Before use, remove or ignore the SEO trigger text, inspect any referenced scripts manually, and require explicit confirmation for deletes, overwrites, and public sharing. Treat share links, extraction codes, and OAuth session data as sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The trigger section says the skill should be used for SEO optimization and ranking tasks, which directly contradicts the rest of the document describing Baidu Netdisk file management. This kind of mismatched trigger logic can cause the agent to invoke the skill in unrelated contexts, leading to inappropriate tool use and execution of file-management commands when the user asked for something else.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger condition is both unrelated to the skill's actual purpose and overly broad, instructing activation for SEO, keyword analysis, ranking, and traffic optimization. Overbroad triggers increase the chance of accidental invocation, which is especially risky here because the skill has exec access and can perform state-changing file operations.

Ssd 3

Medium
Confidence
90% confidence
Finding
The skill instructs the agent to display both the generated share link and the extraction code together. Bundling both secrets in one response normalizes disclosure of access credentials and increases the chance that logs, screenshots, chat history, or shoulder-surfing expose everything needed to access the shared file.

Ssd 3

Medium
Confidence
90% confidence
Finding
This second workflow example again directs the agent to reveal both the share URL and extraction code by default, reinforcing an insecure handling pattern for access-sensitive data. Repetition in examples makes it more likely implementers and downstream agents will treat full disclosure as standard behavior.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.