Supply Chain Risk Monitor

Security checks across malware telemetry and agentic risk

Overview

This is a text-only supply-chain risk analysis skill with no code, credential use, persistence, or hidden data movement.

Reasonable to install. Supply-chain analysis can involve confidential supplier, financial, and operational details, so only provide data appropriate for your agent environment and review recommendations before making business changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrase "Assess our supply chain risk" is broad, generic business language that could plausibly appear in normal user conversation, increasing the chance the skill activates unintentionally. While the skill appears business-focused rather than overtly malicious, broad activation can cause unexpected execution, context capture, or workflow changes when users did not specifically intend to invoke this skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal