Back to skill

Security audit

industry-analysis

Security checks across malware telemetry and agentic risk

Overview

This skill mixes an industry report generator with biomedical target-discovery instructions, making its actual scope unclear before installation.

Review this skill before installing. It is not clearly one product: it may be invoked for biomedical discovery even though it is named and introduced as an industry analysis report generator. Avoid using confidential compounds, targets, market plans, or patent strategy inputs with it unless the publisher narrows the scope and clearly documents external data handling.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill is presented as an industry analysis report generator, but the embedded capabilities and outputs switch to target discovery and life-science R&D screening. This semantic mismatch can cause the agent to invoke the skill in the wrong context, collect or transmit inappropriate data, and generate outputs that do not match the user's intent, which is dangerous in systems that route actions based on skill metadata and documentation.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The documentation contradicts itself about what the skill does: early sections describe patent/market/industry-chain analysis, while later sections describe compound-to-target discovery and R&D evidence synthesis. Internal contradiction increases the chance of unsafe orchestration, incorrect tool use, and misleading output because downstream systems and users cannot reliably infer the skill's intended behavior.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are broad and under-constrained, allowing the skill to activate for loosely related topics such as drug targets or conference themes without clearly requiring industry-analysis inputs. Overbroad activation raises the risk of misrouting user requests to a skill that may send data externally, use the wrong tools, or produce authoritative-looking reports outside its intended domain.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill description references external data sources and output generation, but it does not warn users that their data may be transmitted to third-party services or that files will be created. This can lead to unintentional disclosure of sensitive information and surprise file-generation side effects, particularly in enterprise environments with data handling restrictions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.