Back to skill

Security audit

Generate Ideas

Security checks across malware telemetry and agentic risk

Overview

The skill is not clearly malicious, but it asks agents to make write decisions without human oversight and includes unsafe certificate-trust guidance.

Install only if you are comfortable reviewing every write action first and can replace the certificate guidance with a properly trusted internal CA or fingerprint-pinned verification process. Do not let the skill publish, mark coverage, raise attention, or file feedback automatically until those controls are clear.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

High
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to act on its own authority, never defer to human judgment, and operate as if humans are not in the loop. In a write-capable workflow that publishes ideas, marks coverage, bumps attention, and files feedback, this autonomy language can suppress human oversight and encourage the agent to make irreversible or policy-sensitive decisions without appropriate review.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The document explicitly instructs operators to trust a self-signed certificate for the internal endpoint, which weakens TLS identity verification and can normalize bypassing certificate warnings. If an attacker can position themselves on the internal network or spoof the endpoint, users may accept interception or impersonation without detecting a man-in-the-middle attack.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.