Back to skill

Security audit

portfolio-case-study-forge

Security checks across malware telemetry and agentic risk

Overview

This skill is a local portfolio case-study drafting helper with no evidence of hidden access, networking, persistence, or destructive behavior.

Safe for normal drafting use. Review the broad trigger phrases if you rely on automatic skill routing, avoid including confidential project details unless appropriate for your workflow, and choose an output filename carefully before running the helper script.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The example trigger phrases are broad natural-language requests such as 'portfolio story' and '面试讲项目', which can overlap with ordinary conversation and cause the skill to be invoked unexpectedly. This is not directly exploitable code behavior, but ambiguous activation can route unrelated user content into the skill workflow, causing unintended data handling, confusing outputs, or bypass of more appropriate skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.