← back to api-design-reviewer

SkillSpector · api-design-reviewer

independent scanner by NVIDIA · skill by DylanCkawalec · how it works ↗

CAUTIONmax severity: MEDIUMrisk score: 23

Without declared permissions the skill's intent is opaque and cannot be validated.; Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance …; Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous …

scanned 2026-08-23

Findings (3)

MEDIUMMCP Least Privilegeconfidence: 0.7

Without declared permissions the skill's intent is opaque and cannot be validated.

SKILL.md

MEDIUMMemory Poisoningconfidence: 0.8

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

scripts/breaking_change_detector.py

HIGHTool Misuseconfidence: 0.24

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

references/rest_design_rules.md

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTIONthis skill

Overall severity MEDIUM

WARNING

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete