Back to skill

Security audit

book-digest

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed, instruction-only book study helper with optional web research and an optional suggestion to save reusable book notes.

Install only if you are comfortable with the agent searching the web for public book information. If it offers to create a reusable reference skill for a book, review the generated content and approve the save location before allowing persistence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill’s stated purpose is book comprehension, but it also instructs the agent to create a new standalone skill artifact after completion. That crosses from content assistance into persistent capability creation, which can cause unauthorized side effects, repository modification, and scope creep beyond the user’s immediate reading task.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Directing the agent to create and store a new skill in `research/` is not necessary to fulfill the declared deep-reading function. Unjustified write actions are dangerous because they can persist data, alter the environment, and normalize file creation behavior from loosely related prompts, increasing the chance of misuse or prompt-to-write escalation.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger condition is overly broad because any user-provided text requesting deep analysis can activate the skill. Broad activation increases the chance that the skill will take over unrelated tasks, apply book-oriented behaviors in the wrong context, and reach sensitive instructions such as web lookup or artifact creation when the user did not intend to invoke this workflow.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.