← back to evaluating-llms-harness

SkillSpector · evaluating-llms-harness

independent scanner by NVIDIA · skill by qcmuu · how it works ↗

PASSmax severity: LOWrisk score: 13

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.; Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks an…

scanned 2026-08-23

Findings (2)

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

references/api-evaluation.md

HIGHOutput Handlingconfidence: 0.24

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

references/custom-tasks.md

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASSthis skill

Overall severity LOW (risk score in the safe range)

CAUTION

Overall severity MEDIUM

WARNING

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete