Back to skill

Security audit

creative-origin-engine

Security checks across malware telemetry and agentic risk

Overview

The skill is a creative planning assistant, but it also tells the agent to automatically save cross-project knowledge about user ideas without clear user consent or retention controls.

Review before installing. The planning workflow itself is understandable, but the skill should require explicit permission before writing any notes, disclose exactly where content is saved, avoid storing sensitive ideas by default, and narrow activation to clear creative-planning requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill instructs automatic cross-project knowledge accumulation by writing outputs into local topic files, even though its declared purpose is creative planning rather than persistent storage. This creates unnecessary data retention and cross-task contamination risk, and may store sensitive user ideas, business plans, or personal details without consent.

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The manifest advertises a planning/analysis skill, but the body also defines post-delivery file-based knowledge deposition. This mismatch hides materially different behavior from users and reviewers, undermining informed consent and increasing the chance that data is written locally without expectation.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger keywords are extremely broad and match common requests like '帮我分析' or '帮我想想', making accidental activation likely. In this skill, accidental activation is more dangerous because execution includes multi-agent orchestration, web research, and persistence behavior that exceeds a casual user's expectations.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation section lacks clear scope boundaries and negative examples, so the skill can be selected for ambiguous everyday planning or brainstorming prompts outside its intended domain. While this is primarily a routing/control issue, it increases the chance of unnecessary tool use and unintended processing.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill describes automatic knowledge persistence but gives no user-facing warning that project artifacts may be written to files. This prevents informed consent and can expose confidential strategy, intellectual property, or personal data to later access or reuse.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger scope is very broad, covering generic requests like planning, brainstorming, feasibility analysis, and 'help me analyze/think,' which can cause the skill to activate in many unintended contexts. Overly broad activation increases the chance of prompt hijacking, accidental routing of unrelated sensitive requests into this skill, and reduced user/control-plane predictability.

Ssd 3

Medium
Confidence
96% confidence
Finding
Because this skill handles brainstorming, startup validation, IP incubation, and planning requests, user inputs are likely to contain sensitive business ideas, proprietary concepts, or personal details. Automatic retention across tasks can preserve and later surface that information in unrelated contexts, causing confidentiality and privacy breaches.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.