Back to skill

Security audit

Semantic Creator — Interface to Governed Semantic Layer (Meta-Skill)

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent semantic-layer modeling workflow that writes local review and output files and requires explicit user approval before generation.

Install this if you are comfortable working through a mostly Chinese semantic-modeling workflow. Review the generated HTML decisions carefully and only return approved:true when all pending or blocked decisions are actually resolved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill content is written entirely in Chinese and includes multiple normative instructions in Chinese without offering any user language choice or documenting why Chinese is required. This can cause users or downstream agents to misunderstand approval gates, decision semantics, and security-relevant workflow constraints, leading to incorrect operation or unsafe authorization of later phases.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.