Back to skill

Security audit

Ai Intelligent Access Control

Security checks across malware telemetry and agentic risk

Overview

The skill appears purpose-aligned for access control, but it needs review because it involves biometric and physical access decisions without enough privacy and safety scoping.

Review carefully before installing or using with real doors, badges, cameras, or alarms. Require documented consent, biometric retention/deletion rules, audit logs, operator review, emergency/manual override, and local legal/privacy compliance before deployment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill describes biometric face recognition, card-based entry, permissions, and alarming, but provides no warnings about biometric privacy, retention, false matches, lockout risk, or safety implications of automated access decisions. In an access-control context, missing these disclosures can lead users to deploy the system without understanding privacy, legal, and physical-security consequences, increasing the chance of misuse or harmful misconfiguration.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.