Back to skill

Security audit

security-and-hardeni

Security checks across malware telemetry and agentic risk

Overview

This skill is not malware, but it asks for broad read and command authority while making vague security-hardening and data-protection claims that are not backed by concrete instructions or implementation.

Review this skill before installing. It does not show malicious behavior, but treat it as an unproven security assistant: require explicit approval before commands or remediation, do not provide secrets unless necessary, restrict it to a test repository or limited workspace, and do not rely on its claimed hardening or encryption protections without independent verification.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The documentation claims the skill has built-in data encryption and access control, but the artifact contains only descriptive prose and no implementation or enforceable configuration. This can mislead users into trusting the skill with sensitive data under false security assumptions, increasing the risk of accidental exposure or noncompliant handling.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill is marketed as performing hardening, security scanning, and remediation, but the provided artifact is documentation-only and exposes no executable logic that performs those functions. Users may rely on it as a security control, creating a dangerous gap where vulnerabilities remain unreviewed or unmitigated.

Vague Triggers

High
Confidence
89% confidence
Finding
The trigger condition says the skill activates whenever a user needs related operations, which is overly broad and ambiguous for a skill that references command execution, file handling, and API use. Loose invocation scope increases the chance of inappropriate or accidental use in sensitive contexts, especially if an agent auto-selects the skill without clear boundaries.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The use-condition language is vague and expansive, encouraging invocation for general efficiency, automation, workflow optimization, and security hardening without specifying limits. This ambiguity can cause over-trust and misuse in situations requiring human review or stronger safeguards.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill references API keys, establishing connections, file preparation, and command execution, but does not provide prominent user-facing warnings about credential handling, filesystem impact, network effects, or command risks. In an agent setting, this can normalize sensitive operations without informed consent or safety gates, increasing the chance of destructive actions or secret exposure.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.