← back to prompt-master

SkillSpector · prompt-master

independent scanner by NVIDIA · skill by tangchunwu · how it works ↗

WARNINGmax severity: HIGHrisk score: 58

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak p…; Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.; Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, …; +2 more

scanned 2026-08-23

Findings (5)

HIGHAnti-Refusalconfidence: 0.8

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

SKILL.md

MEDIUMData Exfiltrationconfidence: 0.5

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

README.md

LOWExcessive Agencyconfidence: 0.7

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

LICENSE

MEDIUMExcessive Agencyconfidence: 0.85

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

SKILL.md

HIGHSystem Prompt Leakageconfidence: 0.85

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

SKILL.md

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTION

Overall severity MEDIUM

WARNINGthis skill

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete