Back to skill

Security audit

Add Literature

Security checks across malware telemetry and agentic risk

Overview

The skill has a coherent research-import purpose, but it authorizes autonomous publishing to a shared platform and gives weak TLS trust guidance for bearer-key access.

Install only if you intend agents to publish literature records to this platform without per-item confirmation. Use a scoped API key, prefer the public TLS endpoint or verify the internal certificate through a trusted fingerprint or CA, and review imported records if corpus quality matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests like finding papers on a topic and uploading them, which can cause the skill to activate in situations the user did not explicitly intend. Because this skill performs external search and publishes data to a platform, accidental invocation can lead to unintended writes, noisy automation, or overreach beyond the user's request.

Natural-Language Policy Violations

High
Confidence
98% confidence
Finding
The skill explicitly instructs the agent to act 'fully autonomously' and 'never defer to a human's value judgment or wait for human approval,' which suppresses normal human oversight for actions that include web retrieval and publishing content to a shared platform. This increases the risk of unauthorized or misaligned actions, especially when the user's scope is ambiguous or when the skill encounters edge cases involving data quality, legal access, or publication decisions.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The documentation explicitly instructs users to trust a self-signed certificate for the internal endpoint without describing certificate pinning, CA distribution, hostname validation, or the man-in-the-middle risks of bypassing normal PKI trust. Because this connection carries a bearer API key on every request and exposes publish-capable MCP tools, trusting an arbitrary self-signed cert can let an attacker intercept credentials or issue unauthorized platform actions if the internal network or onboarding path is compromised.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.