Strategy Review

Security checks across malware telemetry and agentic risk

Overview

This skill is a strategy-review assistant whose file reading and optional review artifacts fit its stated purpose, with only a minor caution about broad trigger phrases.

Install if you want an agent to critique strategy documents. Be aware that phrases like "poke holes in this plan" or "what's weak here" may invoke it, so use explicit wording and review any proposed .beagle state files or strategy-review outputs before accepting persistent changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger list includes broad conversational phrases such as 'what's weak here' and 'poke holes in this plan,' which can match ordinary discussion outside a deliberate strategy-review context. Overbroad invocation can cause the wrong skill to activate, leading to unintended file reads, artifact creation, or analysis of sensitive materials the user did not mean to submit to this workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal