Back to skill

Security audit

科研助手

Security checks across malware telemetry and agentic risk

Overview

This is a broad scientific research assistant skill that uses local file and command capabilities for expected research workflows, with no hidden installer, persistence, or exfiltration behavior found.

Install only if you are comfortable giving the agent command execution and local file access for research projects. Review generated commands before running expensive or data-mutating analysis, keep API keys in environment variables, and do not use it for clinical decisions or regulated human/animal research without expert oversight.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The skill describes broad invocation behavior without clear trigger boundaries, making it likely to activate on vague research-related prompts and then use powerful capabilities such as exec, file access, and external retrieval. In an agent setting, overbroad activation increases the chance of unintended tool use on untrusted input, which can lead to unsafe command execution or unnecessary data access.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Claiming full-cycle research support without narrowing scope encourages the agent to treat many unrelated or weakly related prompts as in-scope. Because the skill advertises broad analytical, retrieval, and execution behaviors, this can expand the attack surface for prompt-triggered misuse and accidental execution beyond the user's actual intent.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation explicitly describes writing outputs to project paths and performing command execution, but it does not warn users about the risks of data modification, path misuse, or executing instructions derived from untrusted input. In a skill with read, glob, grep, and exec tools, missing safety constraints materially increases the chance of overwriting files, operating on unintended paths, or turning prompt content into shell commands.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.