Back to skill

Security audit

Agent Native Design

Security checks across malware telemetry and agentic risk

Overview

This is an advisory CLI-design skill with coherent documentation and no hidden data access, persistence, or privileged runtime behavior.

Install if you want agent guidance for designing or auditing CLIs. Be aware it may be auto-selected for relevant CLI-design prompts, and review its recommendations before applying them to tools that handle credentials or destructive operations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill enables implicit invocation without defining any trigger constraints, exclusions, or scoping rules. That increases the chance the skill is auto-selected in unintended contexts, which can cause an agent to apply design guidance or security-relevant CLI recommendations when the user did not explicitly request this skill, expanding behavior in a way that may bypass expected user intent boundaries.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.