Back to skill

Security audit

slack-gif-creator

Security checks across malware telemetry and agentic risk

Overview

The skill is labeled as a Slack GIF helper, but its instructions broaden into generic development automation and data processing while requesting command execution capability.

Review before installing. This does not show malicious code or hidden persistence, but it gives an agent broad read/command-execution authority under instructions that are much wider than Slack GIF creation. Install only if you are comfortable with that scope, or ask the publisher to narrow the description, use cases, and command guidance to Slack-compatible GIF creation and validation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The skill claims to be for Slack GIF creation, but its core-function section instead describes generic data analysis and workflow orchestration. This mismatch can cause the agent to invoke the skill in unrelated contexts, increasing the chance of inappropriate tool use, especially because the skill declares exec capability.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The feature list advertises GitHub-based data processing and traceability capabilities that do not fit a Slack GIF creation skill. In a skill with read and exec tools, this kind of scope expansion is dangerous because it may justify fetching or processing external data and executing commands outside the user's expected task boundary.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documented use cases are generic development, operations, and content automation scenarios rather than Slack GIF creation. This broadens activation conditions and makes the skill more likely to be selected for tasks where exec-enabled behavior is unnecessary or risky.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation condition is overly broad and ambiguous, including generic automation, data analysis, and workflow orchestration language. Because the skill exposes exec, vague routing criteria can cause accidental or unjustified invocation in many contexts, expanding the attack surface and violating least privilege.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.