Back to skill

Security audit

prompt-ab-lab

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent prompt-comparison helper with only a small disclosed local CSV-writing script and no evidence of hidden networking, credential access, or persistence.

Reasonable to install for prompt comparison workflows. Before running the bundled script, provide only JSON files you intend to process and choose a safe CSV output path so you do not overwrite an existing file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Low
Confidence
86% confidence
Finding
The example trigger phrases are broad and generic, such as requests to compare prompts or build an evaluation table, without clear boundaries on when this specific skill should be selected. This can cause over-triggering or incorrect routing, which may lead the agent to apply the skill in unintended contexts and produce irrelevant or misleading outputs.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.