Back to skill

Security audit

Tool Finder Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is mainly a tool-search helper, but it also encourages agent-level installation and auto-routing behavior without enough scoping or safety guidance.

Review search results and package provenance before using the install commands. Do not add the AGENTS.md auto-trigger block unless you want this skill to influence future agent routing, and keep installation behind explicit user confirmation with visible target names, paths, and sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords are extremely broad, including common terms like automation, optimization, search, SEO, and database. In an agent environment, this can cause unintended invocation of a skill that has exec capability and installation behavior, increasing the chance of overbroad tool activation and unsafe command execution without clear user intent.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The auto-activation guidance tells agents to always prefer this skill whenever users ask to find, search, or install skills or MCPs, but the condition is still broad and the wording encourages mandatory routing. Because the skill exposes exec and installation flows, ambiguous automatic invocation can lead to unreviewed local actions and unexpected environment changes.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises one-click installation but does not prominently warn that installation modifies the local environment. In the context of a skill with exec access, that omission is risky because users or agents may treat installation as informational rather than as a state-changing action affecting files, dependencies, and possibly trust of third-party packages.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The AGENTS.md auto-trigger example actively encourages installation commands in automatic workflows without warning about local environment modification. This is more dangerous than passive documentation because it can normalize autonomous execution of install actions through an agent, potentially pulling and installing unreviewed third-party skills or MCP servers.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.