Back to skill

Security audit

Skill Creator Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward AI skill creation helper that writes local skill files as part of its stated purpose, with no evidence of hidden exfiltration, persistence, or destructive behavior.

Install only if you want an agent to help create or edit local skill files. Use it in a dedicated workspace, review generated SKILL.md files before using or publishing them, and confirm any command execution or package installation before allowing the agent to proceed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are broad, generic commands like creating, validating, or optimizing a skill, without clear activation boundaries or confirmation requirements. In an agent environment, such vague triggers can cause unintended activation during normal discussion, which may lead the skill to read, write, or execute actions unexpectedly given that the skill advertises write and exec capabilities.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill explicitly declares read, write, and exec capabilities and includes examples that create local directories and write SKILL.md files, but it does not prominently warn users that these actions can modify the filesystem or invoke the execution environment. This creates a high risk of users triggering state-changing or command-executing behavior without informed consent, especially because the skill is framed as a simple creation tool for everyday use.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.