Back to skill

Security audit

Agent安全工具箱(免费版)

Security checks across malware telemetry and agentic risk

Overview

This skill appears locally contained, but its security-scanner claims materially exceed and conflict with the scanner it provides.

Review this skill carefully before relying on it. It does not show malicious data handling, but its scanner appears incomplete and inconsistent with its documentation, so it should not be treated as a trustworthy installation gate or security audit tool without fixes and tests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The documentation states that Markdown scanning is limited to code blocks, but the provided Python scanner reads every line of `.md` files without implementing any code-block-only filtering. This mismatch can cause false positives and unsafe reliance on scan results, especially if users make installation or trust decisions based on the claimed behavior.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill advertises 24 built-in detection rules, but the embedded scanner code defines only 10 rules. This creates a deceptive security posture: users may believe they are protected against classes of malicious behavior that are not actually checked, leading to missed detection of dangerous skills or code.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.