Software Architecture Design SOP

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only architecture-design skill, with one privacy caution around ML logging guidance but no evidence of hidden execution or data access.

Safe to install for architecture documentation. When using the ML/AI section, avoid blindly logging raw prompts, inputs, outputs, uploaded documents, or personal data; prefer metadata, sampling, redaction, retention limits, encryption, and restricted log access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The guidance explicitly says to log model inputs and outputs for drift monitoring, but provides no guardrails for sensitive data minimization, redaction, consent, retention, or access control. In an ML/AI system context, inference payloads often contain PII, confidential business data, prompts, uploaded documents, or model outputs derived from sensitive inputs, so following this advice naively can create a privacy and data-exposure risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal