Project Manager

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only project management skill with no code, credentials, persistence, or external access requested.

Safe to install as a planning and project-management helper. Treat it like any assistant workflow: avoid entering confidential budgets, stakeholder details, or business plans unless you are comfortable sharing them in the agent conversation, and use explicit wording when you want the project-manager behavior invoked.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The command triggers include broad natural-language phrases such as "Status report," "Risk check," "Health score," and "What's at risk?" that could plausibly appear in ordinary conversation rather than as deliberate invocations. In an agent environment, this creates prompt-trigger ambiguity that may cause the skill to activate unintentionally, leading to unwanted project actions, misleading outputs, or interference with the user's actual task.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal