Back to skill

Security audit

Inversion Strategist

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only problem-solving skill with no evidence of code execution, data access, persistence, or harmful behavior.

Review whether you want a skill with broad phrases like inversion or avoid failure to activate automatically. From the supplied evidence, installation risk appears low because the skill only provides reasoning guidance and does not run code or access data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill advertises multiple broad trigger phrases such as "flip it," "what NOT to do," and "avoid failure," which are common in ordinary conversation and can cause the skill to activate when the user did not specifically intend to invoke it. Unintended activation can lead to inappropriate routing, response confusion, or interference with a more suitable skill, though this skill’s content is not itself high-risk or privileged.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.