← back to scout

SkillSpector · scout

independent scanner by NVIDIA · skill by seaworld008 · how it works ↗

WARNINGmax severity: HIGHrisk score: 77

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstrea…; Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.; Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.; +2 more

scanned 2026-08-23

Findings (8)

HIGHAnti-Refusalconfidence: 0.7

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

reference/multi-engine-mode.md

HIGHAnti-Refusalconfidence: 0.7

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

reference/tri-engine-investigate.md

HIGHData Exfiltrationconfidence: 0.75

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

SKILL.md

HIGHData Exfiltrationconfidence: 0.85

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

reference/advanced-reproduction-triage.md

MEDIUMData Exfiltrationconfidence: 0.6

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

reference/perf-investigation.md

HIGHData Exfiltrationconfidence: 0.255

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

references/advanced-reproduction-triage.md

MEDIUMExcessive Agencyconfidence: 0.75

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

reference/5whys-rca.md

HIGHPrompt Injectionconfidence: 0.7

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

SKILL.md

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTION

Overall severity MEDIUM

WARNINGthis skill

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete