Back to skill

Security audit

Context Mode

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill is a coherent research helper, but users should be careful with command execution and persistent indexing.

Install only if you trust the ctx_* tools available in your environment. Review any generated commands before running them, keep command use read-only unless you explicitly approve changes, and avoid indexing private or sensitive material unless you understand storage and deletion behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes very broad everyday phrases such as '帮我查一下' and '分析一下这些内容', which can cause the skill to activate in situations the user did not intend. In a skill that enables web fetching, indexing, and command execution workflows, accidental invocation can lead to unnecessary external access, data indexing, or expansion of tool use beyond user expectations.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill encourages fetching and indexing webpages and running shell/network commands, but does not warn about risks such as indexing sensitive content, retrieving untrusted remote data, or executing commands over external inputs. In this context, the omission is security-relevant because the skill is explicitly framed as a convenience accelerator, which may normalize risky operations without requiring user awareness or consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.