Agentsop Agent Topology Selection

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only planning skill for choosing agent architectures, with a minor metadata hygiene issue from local authoring paths.

Reasonable to install if you want advisory guidance for multi-agent architecture choices. Be aware it may speak up during broad multi-agent design discussions, and the publisher should remove local machine paths from future releases.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Low
Confidence
95% confidence
Finding
The file includes local absolute filesystem paths in `source_skills`, which can disclose the developer's username, workstation directory layout, and local environment details. While this does not itself enable code execution, it creates unnecessary information disclosure that can aid targeted social engineering, environment fingerprinting, or path-based follow-on attacks if the artifact is shared outside the originating machine.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal