Back to skill

Security audit

Skill Vetter

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed local skill-auditing scanner whose file reads, command execution, and optional batch scan fit its stated purpose.

Use this as a local scanner and prefer explicit target paths. Review `scripts/batch_audit.sh` before running batch mode because it enumerates installed skill directories and report output can include file paths or snippets from scanned skills.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
76% confidence
Finding
If the skill enumerates or batch-scans hardcoded local skill directories beyond the user-supplied target path, it expands access scope beyond the declared single-skill auditing purpose. That can expose unrelated local skills, secrets embedded in them, or metadata about the user's environment without clear user intent, making the skill more privacy-invasive than advertised.

Vague Triggers

Medium
Confidence
78% confidence
Finding
Broad trigger phrases like 'audit skill' or 'skill 检查' can cause accidental invocation during ordinary conversation, especially in environments where users discuss skills frequently. Because this skill has `exec` and `read` capabilities, unintended activation could lead to file access or command execution when the user did not mean to run an audit.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.