Back to skill

Security audit

Remix Auth Tool Free

Security checks across malware telemetry and agentic risk

Overview

This Remix API-key helper has a coherent auth purpose, but its broad trigger text and vague create/delete/export instructions could let an agent modify files or run commands beyond that purpose.

Review this skill before installing. It is not showing malicious behavior, but it handles API keys and declares write/exec authority while using broad, generic instructions. Only use it for explicit Remix API authentication setup or verification, keep real keys out of source control, and avoid letting it perform unrelated file edits, exports, imports, or command execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The skill claims to be a narrowly scoped Remix authentication helper, but the documentation broadens behavior into generic create/query/modify/delete/export operations driven by vague parameters. In an agent context, this scope creep can cause the model to perform unrelated file or command actions under the guise of the skill, weakening user expectations and increasing the chance of unintended or unsafe execution.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The activation text is broad enough to match common coding, debugging, and deployment situations well beyond Remix authentication. In agent ecosystems, overly broad triggers can cause an overprivileged skill with exec/write capability to activate in unrelated contexts, increasing the risk of unnecessary secret handling or command execution.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The capability section advertises generic operation modes without precise trigger constraints or safety boundaries. Because the skill also declares read/write/exec tools, this ambiguity can let the agent interpret ordinary user input as authorization to modify configuration, export data, or run commands not strictly necessary for authentication.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.