SkillSpector · traefik
independent scanner by NVIDIA · skill by theheavenlyd3mon · how it works ↗
Without declared permissions the skill's intent is opaque and cannot be validated.; Potential security issue detected. Manual review is recommended.; This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.; +3 more
scanned 2026-08-23
Findings (19)
Without declared permissions the skill's intent is opaque and cannot be validated.
SKILL.md
Potential security issue detected. Manual review is recommended.
SKILL.md
Potential security issue detected. Manual review is recommended.
references/community-patterns.md
Potential security issue detected. Manual review is recommended.
references/docker-provider.md
Potential security issue detected. Manual review is recommended.
references/docker-provider.md
Potential security issue detected. Manual review is recommended.
references/production-deployment.md
Potential security issue detected. Manual review is recommended.
references/production-deployment.md
Potential security issue detected. Manual review is recommended.
references/production-deployment.md
Potential security issue detected. Manual review is recommended.
references/static-configuration.md
Potential security issue detected. Manual review is recommended.
references/static-configuration.md
Potential security issue detected. Manual review is recommended.
references/tcp-routing.md
Potential security issue detected. Manual review is recommended.
templates/docker-compose.yml
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
references/community-patterns.md
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
references/community-patterns.md
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
references/operational-audit.md
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
references/operational-audit.md
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
references/operational-audit.md
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
references/community-patterns.md
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
references/community-patterns.md
What the verdicts mean
SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.
Overall severity LOW (risk score in the safe range)
Overall severity MEDIUM
Overall severity HIGH
Overall severity CRITICAL
Scan could not complete