← back to breach

SkillSpector · breach

independent scanner by NVIDIA · skill by seaworld008 · how it works ↗

FAILmax severity: CRITICALrisk score: 100

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, dat…; Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.; Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.; +5 more

scanned 2026-08-23

Findings (16)

MEDIUMExcessive Agencyconfidence: 0.85

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

SKILL.md

MEDIUMExcessive Agencyconfidence: 0.75

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

reference/supply-chain-attack-design.md

HIGHMemory Poisoningconfidence: 0.9

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

reference/ai-red-teaming.md

HIGHMemory Poisoningconfidence: 0.27

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

references/ai-red-teaming.md

LOWPrivilege Escalationconfidence: 0.8

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

reference/ai-red-teaming.md

MEDIUMPrivilege Escalationconfidence: 0.7

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

reference/attack-playbooks.md

HIGHPrompt Injectionconfidence: 0.7

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

SKILL.md

HIGHPrompt Injectionconfidence: 0.8

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

reference/ai-red-teaming.md

HIGHPrompt Injectionconfidence: 0.9

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

reference/ai-red-teaming.md

HIGHPrompt Injectionconfidence: 0.27

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

references/ai-red-teaming.md

HIGHServer-Side Request Forgeryconfidence: 0.9

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

reference/attack-playbooks.md

HIGHServer-Side Request Forgeryconfidence: 0.27

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

references/attack-playbooks.md

HIGHYARA Matchconfidence: 0.8

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

SKILL.md

HIGHYARA Matchconfidence: 0.8

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

SKILL.md

HIGHYARA Matchconfidence: 0.8

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

reference/ai-red-teaming.md

HIGHYARA Matchconfidence: 0.8

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

references/ai-red-teaming.md

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTION

Overall severity MEDIUM

WARNING

Overall severity HIGH

FAILthis skill

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete