Back to skill

Security audit

skill-tester-cn

Security checks across malware telemetry and agentic risk

Overview

This skill appears intended for testing other skills, but it can actively run target-skill behavior and write reports without clear safety boundaries.

Install only if you intend to let the agent inspect other skills and possibly run their test workflows. Prefer using it on trusted skills, ask for simulated or static-only testing first when reviewing unknown skills, and choose or confirm the report output path before running active tests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
该技能不仅分析目标技能定义,还明确要求对目标技能引用的脚本、资源进行“执行测试”,这会把一个本应偏静态/功能评估的技能扩展为可主动运行第三方代码的执行器。若被测试的技能包含恶意脚本、危险命令或副作用操作,测试器会在较少审查和隔离的情况下触发它们,造成代码执行、数据破坏或凭据泄露。

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are generic enough to overlap with ordinary user requests about testing or checking a skill, which can cause the skill to activate unexpectedly. Because this skill may analyze another skill, generate files, and run tests, accidental invocation expands the attack surface and can lead to unintended actions on local skill content.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README describes analysis and testing behavior but does not clearly warn that the skill may execute tests against another skill and generate output files. This lack of disclosure can mislead users about side effects, increasing the risk of unintentional file creation, modification of workspace state, or execution of risky test flows against untrusted skill definitions.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
技能会在当前工作目录自动写出测试报告,但没有在用户可见层面提前声明会创建文件、文件名格式、写入位置或覆盖策略。攻击者可借此诱导产生意外落盘、污染仓库工作区、泄露被测技能内容摘要,或在自动化环境中触发不期望的文件副作用。

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.