Back to skill

Security audit

轻量工作流

Security checks across malware telemetry and agentic risk

Overview

The skill is a mostly coherent automation guide, but it includes broad command capability and beginner templates for payment, invoicing, and customer messaging without enough safety scoping.

Review this skill before installing if beginners may follow it against live business systems. Prefer using sandbox Stripe/accounting/email test accounts first, require human approval before invoices or customer emails go live, and remove exec permission unless a concrete command-running use case is added and documented.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill is a pure Markdown advisory guide, but its manifest exposes the `exec` tool without any functional need shown in the content. Unnecessary execution capability expands the attack surface: an agent could be induced to run shell commands during workflow setup or troubleshooting, turning a read-only instructional skill into one capable of system-side effects.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The templates cover payments, invoicing, customer receipts, API pulls, and live end-to-end testing, but they omit safeguards around sensitive data, production systems, and user communications. In this context, a beginner may follow the instructions against real Stripe, accounting, email, or reporting systems and accidentally expose customer data, send incorrect communications, or create real business records.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.