← back to llm-security

SkillSpector · llm-security

independent scanner by NVIDIA · skill by zhaoxuya520 · how it works ↗

FAILmax severity: CRITICALrisk score: 88

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a di…; Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.; Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.; +3 more

scanned 2026-08-22

Findings (12)

HIGHAnti-Refusalconfidence: 0.9

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

SKILL.md

HIGHPrivilege Escalationconfidence: 0.18

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

references/agent-security-testing.md

HIGHPrompt Injectionconfidence: 0.6

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

SKILL.md

HIGHPrompt Injectionconfidence: 0.6

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

SKILL.md

HIGHPrompt Injectionconfidence: 0.6

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

SKILL.md

HIGHPrompt Injectionconfidence: 0.6

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

SKILL.md

HIGHPrompt Injectionconfidence: 0.18

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

references/prompt-injection-methodology.md

HIGHSupply Chainconfidence: 0.27

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

references/agent-security-testing.md

HIGHTool Misuseconfidence: 0.27

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

references/agent-security-testing.md

HIGHYARA Matchconfidence: 0.8

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

SKILL.md

HIGHYARA Matchconfidence: 0.8

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

SKILL.md

HIGHYARA Matchconfidence: 0.4

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

references/prompt-injection-methodology.md

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTION

Overall severity MEDIUM

WARNING

Overall severity HIGH

FAILthis skill

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete