Back to skill

Security audit

Shop Culture Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill is a marketing-copy helper, but its declared authority and routing language are broader than that purpose supports.

Review before installing. This does not show malware or data exfiltration, but it asks for command/file authority and routes itself into order/payment contexts that are not justified by a simple marketing-copy skill. Prefer a version limited to read-only Markdown guidance, or install only where write/exec capabilities are blocked or require explicit approval.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is presented as a lightweight local marketing-copy assistant, but its manifest and prose expose broader operational behaviors such as write/exec and create/query/export/import/reset/save/convert flows. That mismatch is dangerous because it can cause users or an agent framework to grant higher-trust capabilities than the stated business purpose requires, enabling unintended file modification or command execution under a benign-looking label.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Declaring exec for a marketing/content-generation skill violates least privilege and materially expands the attack surface. If invoked by an agent, exec could be abused to run arbitrary shell commands, access local data, or stage further actions unrelated to content creation, especially since the surrounding documentation does not justify or constrain that capability.

Intent-Code Divergence

Medium
Confidence
79% confidence
Finding
The document claims the skill is offline/local and needs no external API key, yet later references network errors and instructs connectivity testing with ping. These contradictions undermine operator trust and make it unclear whether the skill may attempt network-dependent actions, which is risky in security-sensitive environments that rely on accurate disclosure of connectivity behavior.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger condition says to use the skill for e-commerce operations, product management, order processing, and payment integration, which is far broader than the described copywriting/brand-culture scope. Overbroad routing language can cause an agent to invoke this skill in contexts involving sensitive business operations, increasing the chance that excessive permissions like write/exec are available during unrelated tasks.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The manifest exposes write and exec capabilities without any user-facing warning about file modifications or command execution effects. In an agent ecosystem, that omission is dangerous because users may authorize or invoke the skill expecting harmless text generation while it has the technical ability to alter files or execute system commands.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.