Back to skill

Security audit

Poc Battle Card

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only sales analysis skill; the only notable issue is garbled manifest text, not unsafe behavior.

Reasonable to install as a lightweight sales prompt skill. Review generated competitive claims before using them with customers, especially because the manifest description is garbled and business POC details may be sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest description is malformed and does not clearly communicate the skill’s purpose, scope, or constraints. This can cause the skill to be invoked in unintended contexts and makes it harder for users or automated systems to assess whether the skill is appropriate and safe to run.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
The garbled/unreadable description suggests an encoding or localization issue that obscures the manifest’s meaning. While not directly exploitable as code execution, it reduces transparency, impairs review, and can hide unsafe behavior or activation intent from users and security tooling.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.