Back to skill

Security audit

Smart Hardware Reference

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a smart-hardware reference library, but it tells the agent to automatically install and load another skill when activated.

Review before installing. The bundled reference content appears non-executable and useful, but install it only if you are comfortable with the agent automatically installing/loading `universal-task-os`; otherwise require UTOS to be installed separately through an explicit trusted flow or use the material as read-only reference content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill presents itself as a non-executing reference repository, yet its activation flow instructs the system to detect, install, and load another skill automatically. This creates an implicit execution and dependency-fetch path that can expand privileges, introduce unreviewed code, or trigger behavior the user did not explicitly request.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
Although described as a reference knowledge base, the usage rules direct the agent to delegate tasks, content generation, and pipeline execution to UTOS. This mismatch can mislead operators and users about the skill's effective behavior, increasing the chance of unintended task execution and data flow into another skill.

Intent-Code Divergence

Low
Confidence
86% confidence
Finding
The documentation claims the skill degrades to read-only mode without UTOS, but also says activation should attempt auto-installation every time. That contradiction weakens operator expectations and can bypass a supposed safe fallback by turning a passive reference skill into an active dependency installer.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list contains broad terms such as IoT, hardware, embedded, firmware, and certification-related keywords that may match many unrelated conversations. Overly broad activation can cause the skill to be invoked unexpectedly, increasing the risk of unwanted delegation, context leakage, or user confusion.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.