Back to skill

Security audit

performance-optimiza

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a generic automation package with command execution and credential/API guidance that is broader than its performance-optimization label explains.

Review this skill carefully before installing. It does not show malicious behavior, but it asks for command execution and gives broad credential/API/file-operation guidance without narrow performance-specific limits. Use it only in a controlled workspace and require explicit approval before it reads sensitive files, uses credentials, calls external APIs, or runs commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill is presented as a performance optimization tool, but the body mostly documents generic automation, file handling, API use, and command execution. This mismatch can mislead users and downstream agents into granting broader trust or permissions than the stated purpose justifies, increasing the chance of unsafe use.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill advertises performance optimization but explicitly includes API key configuration, file operations, and command execution without showing why those powerful capabilities are necessary for that goal. In a skill with exec enabled, this unjustified breadth materially raises the risk of credential misuse, arbitrary local actions, or harmful side effects if invoked by an agent.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger condition states the skill should activate whenever a user needs 'related operations,' which is so broad that an agent may invoke it in unintended contexts. Because the skill also references command execution, file handling, and API usage, accidental invocation could cause unexpected external actions or access to sensitive resources.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation mentions API calls, file processing, and command execution in troubleshooting and configuration guidance, but does not prominently warn users that the skill may read files, use credentials, or run commands. This weak disclosure undermines informed consent and increases the risk that an agent or user will permit dangerous actions without understanding their impact.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.