adaptive-suite

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but it needs review because it can catalog NAS file metadata and asks for vague API-key access without clear limits.

Install only if you are comfortable with a broad assistant skill. Before using the NAS scraper, require explicit user-selected directories, sensitive-share exclusions, local-only result storage, and deletion controls. Do not provide a broad FREE_API_KEYS bundle; use separate least-privilege keys for named services only.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill declares a very broad scope spanning coding, business analysis, project management, web development, data analysis, and NAS scraping. Overly general invocation criteria increase the chance the agent will activate this skill in unrelated contexts, expanding access to tools and sensitive workflows beyond what is necessary and weakening least-privilege boundaries.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal