← back to network-101

SkillSpector · network-101

independent scanner by NVIDIA · skill by Dokhacgiakhoa · how it works ↗

WARNINGmax severity: HIGHrisk score: 71

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.; Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain…; Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.; +2 more

scanned 2026-08-23

Findings (15)

MEDIUMPrivilege Escalationconfidence: 0.7

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

sub-skills/3-configure-snmp-service-port-161.md

MEDIUMPrivilege Escalationconfidence: 0.7

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

sub-skills/4-configure-smb-service-port-445.md

MEDIUMPrivilege Escalationconfidence: 0.7

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

sub-skills/5-analyze-service-logs.md

MEDIUMPrivilege Escalationconfidence: 0.7

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

sub-skills/example-2-snmp-testing-setup.md

MEDIUMPrivilege Escalationconfidence: 0.7

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

sub-skills/example-3-smb-anonymous-access.md

MEDIUMPrivilege Escalationconfidence: 0.8

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

sub-skills/example-3-smb-anonymous-access.md

MEDIUMRogue Agentconfidence: 0.8

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

sub-skills/1-configure-http-server-port-80.md

HIGHTool Misuseconfidence: 0.75

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

sub-skills/1-configure-http-server-port-80.md

HIGHTool Misuseconfidence: 0.8

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

sub-skills/4-configure-smb-service-port-445.md

HIGHTool Misuseconfidence: 0.75

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

sub-skills/example-1-complete-http-lab-setup.md

HIGHTool Misuseconfidence: 0.8

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

sub-skills/example-3-smb-anonymous-access.md

HIGHYARA Matchconfidence: 0.35

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

sub-skills/2-configure-https-server-port-443.md

MEDIUMYARA Matchconfidence: 0.65

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

sub-skills/4-configure-smb-service-port-445.md

MEDIUMYARA Matchconfidence: 0.65

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

sub-skills/common-enumeration-tools.md

MEDIUMYARA Matchconfidence: 0.65

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

sub-skills/service-verification-commands.md

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTION

Overall severity MEDIUM

WARNINGthis skill

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete