Digital IP Agent

Security checks across malware telemetry and agentic risk

Overview

This is a text-only skill for generating synthetic creator-style agent packages, with no hidden code or automatic system access, but users should avoid presenting outputs as the real person.

Install only if you intentionally want to create synthetic agents based on public personas. Clearly label generated agents as unofficial, avoid implying endorsement or identity, review generated soul.md, identity.md, memory.md, and agents.md before use, and be cautious before adding recommended memory, browser, or code-execution skills.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill’s activation description uses very broad phrases like "clone this creator's style" and "generate agent files from this public persona," which overlap with ordinary user requests and lack strong scoping constraints. This can cause the skill to activate in ambiguous situations and route users into generating impersonation-oriented persona packages for real people without sufficient checks, increasing the risk of misuse and policy-bypassing behavior.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal