Ops

Security checks across malware telemetry and agentic risk

Overview

This is a broad operations guidance skill, but it is only a Markdown instruction file and does not request code execution, credentials, network access, persistence, or automatic authority.

Install if you want general operations help across incidents, deployments, meetings, vendors, and documentation. Keep humans in the loop for production changes, incident decisions, vendor negotiations, and any sensitive operational information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description is extremely broad and functionally covers many organizational domains without clear boundaries, triggers, or exclusions. In an agent system, this can cause over-invocation or inappropriate delegation into sensitive operational workflows, increasing the chance the agent acts on high-impact tasks without sufficient scoping, approval gates, or context-specific safeguards.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal