AI Safety Audit

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only AI safety audit checklist with no code execution, credential use, persistence, or hidden data movement.

Safe to install as a structured audit aid. Use it with clearly scoped inputs, avoid sharing unnecessary confidential system details, and verify regulatory conclusions, cost estimates, and paid linked resources with qualified compliance or security professionals before relying on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill states only that it acts 'when activated' and describes broad audit behavior, but it does not define clear trigger phrases, scope limits, or preconditions. In an agent environment, this ambiguity can cause the skill to run unexpectedly on loosely related prompts, leading to inappropriate data collection, unintended compliance assertions, or interference with other workflows.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal