SkillSpector · network-101
independent scanner by NVIDIA · skill by Dokhacgiakhoa · how it works ↗
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.; Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain…; Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.; +2 more
scanned 2026-08-23
Findings (15)
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sub-skills/3-configure-snmp-service-port-161.md
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sub-skills/4-configure-smb-service-port-445.md
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sub-skills/5-analyze-service-logs.md
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sub-skills/example-2-snmp-testing-setup.md
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sub-skills/example-3-smb-anonymous-access.md
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sub-skills/example-3-smb-anonymous-access.md
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
sub-skills/1-configure-http-server-port-80.md
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
sub-skills/1-configure-http-server-port-80.md
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
sub-skills/4-configure-smb-service-port-445.md
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
sub-skills/example-1-complete-http-lab-setup.md
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
sub-skills/example-3-smb-anonymous-access.md
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
sub-skills/2-configure-https-server-port-443.md
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
sub-skills/4-configure-smb-service-port-445.md
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
sub-skills/common-enumeration-tools.md
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
sub-skills/service-verification-commands.md
What the verdicts mean
SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.
Overall severity LOW (risk score in the safe range)
Overall severity MEDIUM
Overall severity HIGH
Overall severity CRITICAL
Scan could not complete