Back to skill

Security audit

Performance Monitor

Security checks across malware telemetry and agentic risk

Overview

This skill provides disclosed SEO reporting and alert-configuration guidance, with no hidden code or unexpected data movement found.

Before installing, be aware this skill may summarize SEO, traffic, ranking, backlink, competitor, and alert-routing information if you connect tools or provide exports. Confirm the intended domain, mode, reporting period or alert baseline, and save location before allowing it to read data or write monitoring memory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill advertises very broad natural-language triggers such as 'generate an SEO report', '出月报', and '排名掉了提醒我', which are common phrases that may appear in ordinary conversations. In agent hosts that rely on loose skill matching, this can cause accidental invocation, leading the agent to collect, summarize, or route sensitive business analytics data when the user did not explicitly intend to activate this skill.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Allowing the shortest valid invocation to be only 'performance-monitor <domain>' is underspecified because it omits a required mode and may omit the reporting period, comparison basis, or alerting scope. This increases the chance of unintended execution paths, default assumptions, or misconfigured monitoring actions, especially in automated environments where a domain token may be present without clear user consent for reporting or alert setup.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.