Back to skill

Security audit

Smart Crawler Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a Notion archive/search helper, but it asks agents to run CLI commands that can mirror private workspace content locally while its scope and read-only claims are partly inconsistent.

Install only if you want an agent to run the smart-crawler CLI and maintain a local copy of selected Notion content. Use a read-only Notion integration token, limit shared pages/databases, set `SMART_CRAWLER_HOME` deliberately, and confirm before any sync, import, reset, delete, or export action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Intent-Code Divergence

High
Confidence
93% confidence
Finding
The skill repeatedly claims strict read-only behavior, yet other sections advertise create/modify/reset/import/export operations. In an agent context with exec capability, this mismatch can mislead users and higher-level orchestration into permitting the skill under a low-risk assumption while it may perform local state changes, file writes, or data transformations beyond read-only access.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger condition is overly broad ('use when database operations, SQL queries, data storage management are needed') and not tightly scoped to this skill's actual Notion-archive use case. In an agent environment, ambiguous activation increases the chance the skill is invoked for unrelated storage or SQL tasks, potentially leading to unnecessary exec use, access to local archives, or handling of sensitive data outside intended bounds.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The capability-coverage keyword list is excessively broad and keyword-driven, which can cause an agent to over-match and activate the skill for loosely related prompts. Because the skill has exec and local storage behavior, accidental invocation expands exposure to command execution and local data handling in contexts where the user did not specifically request this tool.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill describes synchronization, import, reset, and archive storage changes without a clear user warning that local files will be written or modified. In the context of a tool with exec capability and local archive paths, lack of disclosure can lead to silent filesystem changes, accidental overwrites, storage growth, or persistence of sensitive mirrored content on disk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.