SkillSpector · breach
independent scanner by NVIDIA · skill by seaworld008 · how it works ↗
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, dat…; Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.; Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.; +5 more
scanned 2026-08-23
Findings (16)
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
SKILL.md
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
reference/supply-chain-attack-design.md
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
reference/ai-red-teaming.md
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
references/ai-red-teaming.md
Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.
reference/ai-red-teaming.md
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
reference/attack-playbooks.md
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
SKILL.md
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
reference/ai-red-teaming.md
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
reference/ai-red-teaming.md
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
references/ai-red-teaming.md
Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.
reference/attack-playbooks.md
Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.
references/attack-playbooks.md
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
SKILL.md
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
SKILL.md
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
reference/ai-red-teaming.md
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
references/ai-red-teaming.md
What the verdicts mean
SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.
Overall severity LOW (risk score in the safe range)
Overall severity MEDIUM
Overall severity HIGH
Overall severity CRITICAL
Scan could not complete