多Agent团队编排-运营版

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only multi-agent workflow playbook with disclosed, purpose-aligned guidance and no install-time code execution.

Before installing, confirm that any shared directories and spawned-agent permissions are scoped to the project and do not expose secrets or unrelated private workspaces. If you automate the cron-style patterns, define exact schedules, triggers, and human approval points for access or credential-related blockers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Low
Confidence
88% confidence
Finding
The phrase "Every few hours (or on trigger)" is ambiguous because it does not define what the trigger is or what events should and should not start the workflow. In a patterns document, this lack of specificity can lead to overly broad or inconsistent activation of the task-dispatch pattern.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal