Back to skill

Security audit

Project Showcase Enhancer

Security checks across malware telemetry and agentic risk

Overview

This skill has a coherent project-showcase purpose, but it should be reviewed because it can read source code, config files such as .env, and resume/JD content without strong privacy guardrails.

Install only if you are comfortable letting the agent inspect the selected project and any provided resume/JD. Use a limited project folder, remove or redact .env files, tokens, private URLs, and confidential employer or personal details before running it, and confirm the exact paths before analysis begins.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The skill description frames the capability as project analysis and showcase generation, but the body instructs the agent to scan arbitrary project directories, enumerate filesystem structure, read README/package metadata, inspect config files including .env/application.yml, and parse user-provided local documents. That expands the data-access surface beyond what the top-level description transparently discloses, creating a meaningful risk of over-collection of sensitive local information such as secrets, internal paths, dependency metadata, and resume contents.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad enough that normal user requests like 'analyze my project' or 'help me write a project introduction' could activate the skill unexpectedly. Because this skill is designed to read local project code and potentially resume/JD content, accidental invocation can lead to unintended processing of sensitive source code or personal documents without an explicit, high-friction confirmation step.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README states that the skill reads project code, README text, JD files, and resume files, but it does not clearly warn users about privacy implications or sensitive-data exposure. In this context, the skill may process proprietary source code, credentials embedded in configs, and highly sensitive personal/employment information, so lack of explicit data-handling notice increases the risk of inadvertent disclosure or over-collection.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger phrases are broad enough to match ordinary requests like 'analyze my project' or 'help me write a project intro,' which can cause the skill to activate unexpectedly. In this skill’s context, unexpected activation could expose local project contents or resume text to the workflow without the user clearly intending to invoke this specific skill.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README states that the skill reads project directories and parses uploaded resume files, but it does not clearly warn users about privacy implications, sensitive data exposure, or how extracted content is handled. Because source trees and resumes commonly contain secrets, proprietary code, personal identifiers, and employment history, insufficient disclosure increases the risk of users sharing sensitive material unintentionally.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are very broad and overlap with ordinary user requests such as 'analyze my project' or 'help me write a project introduction'. In a skill system that auto-invokes behaviors, this can cause unintended activation on repositories or files the user did not mean to process, increasing the chance of accidental data exposure or unnecessary file access.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README says the skill reads project directories and parses resume files, but it does not clearly warn users that source code, configuration content, and personal resume data may be ingested and summarized. In this context, missing privacy and data-handling disclosures is risky because users may provide sensitive code, secrets in configs, or personal information without informed consent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation cues are broad enough to match many ordinary 'help me look at my project' requests, which can cause the skill to trigger in contexts where the user did not intend deep local scanning or document parsing. Because this skill can access local project structure and related files, accidental invocation increases the chance of unnecessary data exposure and confusing consent boundaries.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger reference section uses ambiguous, generic phrasing like analyzing, reviewing, showcasing, or preparing interview material for a project, without clear boundaries or exclusions. In a skill that instructs local codebase scanning and file parsing, ambiguous invocation language raises the risk that the agent performs broader inspection than the user expected.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The script reads repository README content and package metadata from any user-supplied path and prints them to stdout for downstream LLM consumption. While this is not inherently credential theft, it creates a real data-exposure risk because repository contents may contain internal URLs, operational details, personal information, or other sensitive material, and the tool does not present consent, minimization, or redaction safeguards.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, common-language requests such as analyzing or describing a project, which can cause the skill to activate in contexts the user did not explicitly intend. In this skill, unintended activation is more concerning because the advertised workflow includes reading codebases, README content, resumes, and JD material, potentially exposing sensitive project or personal data to the wrong skill path.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The description states that the skill reads project code, README files, resumes, and job descriptions but does not warn users that these inputs may contain secrets, proprietary source code, personal information, or other sensitive data. Because the skill is explicitly positioned to ingest multiple high-sensitivity document types, omission of privacy guidance materially increases the risk of accidental data disclosure.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.