Write Plan

Security checks across malware telemetry and agentic risk

Overview

This is a simple planning prompt skill with some noisy extra references, but it does not install code, access data, or request privileges.

Safe to install for generating implementation plans. Users should be aware it may activate on generic planning requests, and the publisher should narrow the trigger terms and remove unrelated learning links to reduce confusion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill documentation is contaminated with unrelated embedded learning/source material, including external video links and product-like references that do not support the stated implementation-planning purpose. This increases the risk of prompt confusion, hidden instruction channels, data provenance issues, and accidental activation of irrelevant behavior, especially because all skill content must be treated as potentially adversarial.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrase and activation examples are broad enough to match common requests such as 'plan', '步骤', or '规划', which can cause the skill to activate outside its intended scope. Overbroad activation increases the chance of unintended invocation, context hijacking, and user confusion, particularly when the skill also contains noisy unrelated content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal