Back to skill

Security audit

Pg Job Queue Free

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a PostgreSQL job-queue guidance document, but it asks for write and command-execution authority while describing itself as a pure knowledge-base skill, so users should review it before installing.

Install only if you are comfortable with the hosting agent having write and command-execution capability in a PostgreSQL-related workflow. Treat generated SQL as advisory, review it before running, use a non-production database first, and keep database credentials out of the skill files and prompts unless intentionally needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill repeatedly presents itself as a 'pure knowledge-base' assistant, but it also advertises create/query/export flows and has write/exec capabilities in the manifest. This mismatch can cause an agent or user to treat the skill as low-risk advisory content when it is actually capable of modifying files or invoking commands, increasing the chance of unintended execution or data changes.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
Claiming '无需安装额外依赖' and '纯知识库型' while declaring write and exec tools understates the operational power of the skill. That discrepancy weakens user trust boundaries and may lead the host agent to invoke a skill with system-modifying capabilities in contexts where only passive guidance was expected.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The document describes the skill as markdown-driven advisory content, but later classifies it as 'MD+EXEC' and mentions exec-based diagnostics. Mixed messaging about whether the skill only advises or can execute commands creates a security-relevant ambiguity that can result in unsafe invocation, especially in environments where exec reaches local shells or database clients.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill declares write/exec support and mentions create/export operations, but it does not provide clear user-facing warnings about command execution, file modification, or database state changes. In a skill that may operate near database tooling, missing disclosure and consent boundaries increase the risk of accidental destructive actions or sensitive data handling.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.