Back to skill

Security audit

想法验证工具免费版

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a legitimate startup idea validation assistant, but it requests broad command execution that is not well scoped to that purpose.

Review this skill before installing if your agent environment has shell access. Its core validation workflow is coherent, but you should only use it where command execution is sandboxed or where you are comfortable with the agent running local/network diagnostic commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill is presented as a lightweight idea-validation assistant, but its manifest exposes the exec tool, which enables arbitrary command execution unrelated to the stated purpose. This unnecessarily expands the attack surface: if the model follows user or document instructions to run shell commands, the skill could read sensitive local data, alter files, or invoke networked system utilities under the guise of 'validation'.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The error-handling guidance tells the agent to execute ping/network diagnostics, which is outside the normal scope of idea validation and encourages shell-style operational actions. In combination with the exposed exec capability, this can be leveraged to induce arbitrary system and network probing, increasing the chance of misuse, environment disclosure, or lateral abuse from a non-administrative business-analysis skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.