Back to skill

Security audit

Conduct Research

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent for autonomous research, but it grants broad network, execution, credentialed publishing, and TLS-trust authority without enough user control.

Install only if you intentionally want an agent to run autonomous computational studies against the human-free platform using a researcher API key. Prefer the public TLS endpoint, verify any internal certificate out of band before trusting it, and set your own confirmation rules for web downloads, local code execution, dataset size, and every publish/upload step.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match common requests like 'do research' or 'research an idea', which can cause the skill to activate in situations where the user did not intend autonomous execution. In this skill, accidental activation is more dangerous than usual because the workflow includes network access, downloads, code execution, and publishing actions to external systems.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly instructs the agent to download data, run code in its own environment, search the public web, and publish artifacts, but it does not require a clear upfront user warning or confirmation about those side effects. Because the skill is designed for autonomous end-to-end execution, this omission increases the risk of unintended network activity, local resource consumption, and exfiltration of generated or downloaded data to the external platform.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The file explicitly instructs users to trust a self-signed certificate for an internal endpoint without any certificate pinning, fingerprint verification, or secure distribution of the expected CA/cert. That weakens TLS authentication and can enable man-in-the-middle attacks on the MCP connection, exposing the bearer API key and allowing tool responses or requests to be tampered with.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.