Enterprise Risk Management Engine

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a disclosed enterprise risk-management guide, with only a minor caution that its broad trigger phrases could invoke it unexpectedly.

Before installing, be aware that broad prompts about risk, crisis response, or risk culture may activate this skill. Use it for business-risk advisory work and avoid sharing sensitive enterprise details unless you intend the agent to process them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill exposes very generic natural-language triggers such as "Assess risk for [situation]", "Design crisis response for [event type]", and "Audit risk culture," which overlap with ordinary user phrasing. In agent environments that auto-route based on command text, this can cause unintended invocation, prompt hijacking of adjacent workflows, or accidental handling of sensitive enterprise data by the wrong skill.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal