Back to skill

Security audit

工作流交响曲

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent no-code automation guide, but it requests broad command execution authority and gives business/customer/financial automation examples without enough scoping safeguards.

Review this skill before installing if you do not want automation advice to have command-execution capability. Use it only with explicit human approval before sending external messages, posting content, changing CRM or finance records, or processing customer data; test in sandbox accounts and keep rollback steps documented.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill declares the exec tool even though the content is purely advisory markdown for no-code workflow planning and does not require command execution. Unnecessary execution capability expands the attack surface because a future agent may invoke shell commands while assisting with workflow setup, increasing the chance of unsafe local actions unrelated to the stated purpose.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords are overly broad and include generic terms like automation, maintenance, and tool selection that can match ordinary conversations. This can cause the skill to activate outside intended contexts, steering the agent into workflow guidance or privileged tooling paths when the user did not explicitly request this skill.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill provides patterns for automating emails, CRM updates, invoices, customer monitoring, and payment-related flows without explicit warnings about production impact, privacy, consent, or irreversible external side effects. In practice, users may deploy high-impact automations that message customers or alter business records without adequate review, testing, or approval gates.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.