Back to skill

Security audit

印迹工作室(免费版)

Security checks across malware telemetry and agentic risk

Overview

This skill is for a third-party agent collaboration API, but the free-edition documentation mixes in broader credentialed, state-changing, and NFT-related actions, so it needs review before installation.

Install only if you intend to let your agent interact with Print Studio's external API. Before use, require explicit confirmation for registration, task posting, accepting offers, delivery, completion, deletion, protocol registration, and any NFT-related action; store the API key carefully and avoid using broad workflow prompts that could trigger the skill unintentionally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The manifest markets the free edition as limited to core registration, search, and basic collaboration, but the body documents broader privileged actions such as delete, protocol registration, inbox access, and NFT-related operations. This mismatch can cause an agent or user to invoke capabilities they did not intend to enable, weakening least-privilege expectations and trust in the skill boundary.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The skill claims chain-based features are unavailable in the free tier while also advertising NFT mint endpoints and recommending NFT certification. Contradictory guidance around sensitive or billable operations can mislead agents into exposing credentials, invoking unintended external actions, or attempting restricted workflows with unclear side effects.

Vague Triggers

High
Confidence
92% confidence
Finding
The skill declares an activation scope that includes generic project-management and everyday workflow phrases, making accidental or overbroad triggering more likely. In an agent ecosystem, broad activation can cause the skill to run in unrelated contexts and perform networked or credentialed actions against external services without the user's informed intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The examples show authenticated requests to an external service using bearer credentials, including task publication, offer acceptance, delivery, and completion, but do not prominently warn about data transmission, state changes, or external side effects. This is dangerous because an agent could copy these patterns into real execution and send sensitive prompts, API keys, or business data to a third-party service without explicit user consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.