Back to skill

Security audit

Planning And Task Breakdown

Security checks across malware telemetry and agentic risk

Overview

This skill is framed as task planning, but it requests command execution and describes API credentials, integrations, batch processing, and automation beyond that purpose.

Review before installing. This may be acceptable only if you intend to give a planning skill command execution and external API capability; otherwise, remove exec/API guidance or restrict it to explicit, user-approved, narrowly scoped actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill is presented as a simple task-breakdown tool, but the documentation also suggests broader operational abilities such as automation, workflow handling, and other execution-adjacent behaviors. This mismatch increases the chance that users or an agent platform will grant the skill more trust or broader invocation than intended, creating a deceptive capability boundary and enabling misuse under an innocuous label.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The documentation references command execution even though the stated purpose is task planning and breakdown. In a skill that has the exec tool declared, undocumented or unjustified command-execution behavior can lead to arbitrary local actions, unintended system changes, or abuse by prompting the agent to run commands under a benign-sounding skill.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The skill documentation includes API calls and external connectivity that are not justified by a task-breakdown use case. This creates risk of silent data exfiltration, transmission of sensitive prompts or files to third parties, and unexpected use of credentials under the guise of a harmless planning utility.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation guidance is broad enough to match many generic productivity and automation requests, making over-invocation likely. Because the skill also advertises capabilities beyond planning, broad triggering increases the chance it will be selected in contexts where users did not expect execution, network access, or other higher-risk behavior.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The user-facing description does not clearly warn that the skill may involve command execution, despite the declared exec capability and later operational language. This undermines informed consent and can cause users to invoke a seemingly harmless planning skill that is actually capable of performing system actions.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The deployment guidance instructs users to configure API keys, initialize external connections, and perform API calls without a clear warning about credential handling or outbound data transfer. In a skill framed as planning/task breakdown, this omission is especially risky because users may expose secrets or sensitive content to external services they did not expect to be involved.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.