Back to skill

Security audit

Ssl Toolkit Free

Security checks across malware telemetry and agentic risk

Overview

This SSL/TLS helper is mostly purpose-aligned, but its activation scope conflicts with its stated purpose while it also provides server-changing certificate and web-server commands.

Review before installing. Use it only for explicit SSL/TLS and HTTPS tasks, and treat any certbot, acme.sh, Nginx/Apache, or cron guidance as requiring your confirmation, backups, and validation on the target server. The project-management trigger should be fixed because it can cause the skill to activate in unrelated work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The trigger-condition text says the skill should be used for project management, task planning, progress tracking, and team collaboration, which clearly conflicts with the actual SSL/TLS functionality. In an agent ecosystem, contradictory routing metadata can cause the skill to activate in unrelated contexts, increasing the chance that users receive infrastructure-changing HTTPS guidance when they asked for something else.

Vague Triggers

High
Confidence
98% confidence
Finding
These trigger conditions are both contradictory and broad, making activation scope unpredictable. When combined with exec/write capabilities, ambiguous routing can lead the agent to invoke a skill that recommends or performs server-affecting operations in the wrong task context, creating a meaningful risk of misconfiguration or unauthorized changes.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill states it will auto-activate on a wide keyword list including generic terms around SSL/TLS and troubleshooting, without clear boundaries or exclusions. Broad keyword activation raises the chance of accidental invocation in partial matches or incidental mentions, which is especially risky because the skill can produce executable commands and configuration changes.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This section provides commands and configuration examples that can modify certificate state, web-server behavior, and scheduled renewal, but it does not prominently warn about side effects such as service disruption, overwriting configs, rate limits, or exposing private-key paths. In context, the skill is operationally legitimate, but because it has exec/write capability, missing safety warnings materially increases the risk of harmful or unintended system changes.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.