← back to ml-paper-writing

SkillSpector · ml-paper-writing

independent scanner by NVIDIA · skill by qcmuu · how it works ↗

WARNINGmax severity: HIGHrisk score: 65

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.; Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, …; Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, dat…; +4 more

scanned 2026-08-23

Findings (17)

MEDIUMMCP Rug Pullconfidence: 0.7

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

SKILL.md

LOWExcessive Agencyconfidence: 0.7

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

templates/aaai2026/aaai2026-unified-template.tex

LOWExcessive Agencyconfidence: 0.7

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

templates/aaai2026/aaai2026.sty

MEDIUMExcessive Agencyconfidence: 0.8

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

templates/icml2026/example_paper.tex

MEDIUMMemory Poisoningconfidence: 0.8

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

templates/colm2025/colm2025_conference.sty

MEDIUMMemory Poisoningconfidence: 0.8

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

templates/colm2025/fancyhdr.sty

MEDIUMMemory Poisoningconfidence: 0.8

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

templates/colm2025/fancyhdr.sty

MEDIUMMemory Poisoningconfidence: 0.8

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

templates/iclr2026/fancyhdr.sty

MEDIUMMemory Poisoningconfidence: 0.8

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

templates/iclr2026/fancyhdr.sty

MEDIUMMemory Poisoningconfidence: 0.8

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

templates/iclr2026/iclr2026_conference.sty

MEDIUMMemory Poisoningconfidence: 0.8

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

templates/icml2026/fancyhdr.sty

MEDIUMPrivilege Escalationconfidence: 0.7

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

templates/README.md

MEDIUMRogue Agentconfidence: 0.75

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

templates/colm2025/fancyhdr.sty

MEDIUMRogue Agentconfidence: 0.75

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

templates/iclr2026/fancyhdr.sty

MEDIUMRogue Agentconfidence: 0.75

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

templates/icml2026/fancyhdr.sty

HIGHTool Misuseconfidence: 0.75

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

templates/neurips2025/Makefile

HIGHTool Misuseconfidence: 0.75

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

templates/neurips2025/Makefile

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTION

Overall severity MEDIUM

WARNINGthis skill

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete