Back to skill

Security audit

University App Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is mainly an astrology tool, but its metadata and instructions advertise broader finance, analytics, write, and execution capabilities that are not clearly scoped.

Install only if you intend to use it for astrology-style birth-chart entertainment, and review/limit its read, write, and execution permissions. The skill should be narrowed before broad deployment because its routing metadata may cause agents to select it for unrelated finance or analytics tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The manifest combines a narrow astrology/personal consultation tool with unrelated enterprise data-analysis, reporting, statistics, and visualization use cases. This creates semantic mismatch that can mislead routing systems or users into invoking the skill in contexts it was not designed for, increasing the chance of inappropriate access to read/write/exec capabilities.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The documentation claims generic create/query/export support via input_params even though the rest of the skill describes fixed astrology analysis features. Overstating capability boundaries can cause an agent to treat the skill as a broader automation interface and pass higher-risk tasks or sensitive data into read/write/exec flows that were never clearly specified.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The file says all calculations are local and no API key is required, but elsewhere declares LLM dependence and mentions network-sensitive behavior. These contradictory trust signals can cause users or agents to assume stronger privacy and isolation guarantees than actually exist, potentially exposing personal birth data or operational metadata to external services.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger text is excessively broad and mismatched, advertising the skill for data analysis, reporting, statistical insights, and visualization despite the actual function being astrology consultation. In agent ecosystems, overbroad invocation cues are dangerous because they can cause the wrong skill to be auto-selected for unrelated tasks, unnecessarily exposing read/write/exec permissions and creating opportunities for prompt-routing abuse.

Vague Triggers

High
Confidence
95% confidence
Finding
The capability scope section lists a large set of broad keywords with little boundary definition, including unrelated analytics and workflow language. This increases unintended invocation and tool overreach risk because agent planners may match on these broad terms and dispatch tasks outside the skill's legitimate domain.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.