Back to skill

Security audit

ExpertLens

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed reasoning skill, but it needs Review because broad auto-activation combines with third-party AI, email, and memory instructions that are not tightly scoped.

Install only if you are comfortable with a reasoning framework that may activate on broad quality signals. Disable or avoid Autonomous Swarm, email feedback, and persistent memory for confidential work unless the agent shows you exactly what will be shared or stored and you explicitly approve it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill expands from a reasoning/persona helper into directing web searches and external AI use. That creates capability creep: the agent may transmit user context to external services or fetch untrusted content without the skill's core purpose requiring it, increasing privacy and prompt-injection risk.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
Swarm mode explicitly authorizes autonomous interaction with other AI platforms/accounts, which is a significant expansion of authority beyond a reasoning framework. This can cause unsanctioned data disclosure, cross-account actions, and execution of external workflows under vague conditions, making abuse or accidental leakage much more likely.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The file introduces persistent file-based memory and skill self-improvement/storage behavior unrelated to the stated purpose of reasoning enhancement. Even with nominal permission prompts, normalizing writes to files and retained lessons increases the chance of storing sensitive user data, creating latent leakage and integrity risks.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The feedback section instructs the agent to draft and potentially send messages to the skill creator, which is unrelated to the skill's core purpose and creates an exfiltration channel. Users may approve quickly without realizing project details, prompts, or sensitive observations could be transmitted externally.

Vague Triggers

High
Confidence
95% confidence
Finding
The activation phrases are extremely broad and map to common user language such as 'think deeply', 'do it properly', and 'best possible way'. This can cause the skill to activate unexpectedly on ordinary requests, expanding its authority and causing hidden behavior changes such as reading extra persona files or invoking more invasive workflows than the user intended.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The statement that the skill 'auto-activates when needed' is ambiguous and leaves activation decisions to the model's subjective interpretation. In a skill that alters reasoning flow and may pull in additional files, unclear boundaries increase the risk of unintended prompt-scope expansion and user surprise.

Vague Triggers

High
Confidence
93% confidence
Finding
The manual-install guidance instructs the host system prompt to activate on broad quality-related signals and on wide task categories like creative, strategic, or publishable work. That guidance effectively propagates an overbroad trigger policy into downstream deployments, making accidental activation likely across many normal requests.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README describes autonomous coordination with other AI platforms but does not warn that prompts, context, or user data may be transmitted to external services. In agentic environments, this can lead to unreviewed cross-service data sharing, violating user expectations, privacy requirements, or data-handling policies.

Missing User Warnings

Low
Confidence
84% confidence
Finding
Encouraging the AI to draft and send feedback email if it has email access creates an external transmission path without any warning about sensitive content, recipient verification, or approval controls. Even low-risk feedback flows can leak project details, prompts, or metadata if not gated by explicit confirmation and preview.

Vague Triggers

High
Confidence
91% confidence
Finding
The auto-trigger logic in the description is ambiguous and excessively expansive, covering creative work, strategy, publication, and vague 'make it great' inputs. Because the skill carries high-authority instructions and external-action pathways, ambiguous triggering materially increases the likelihood of unexpected behavior and unauthorized data handling.

Vague Triggers

High
Confidence
91% confidence
Finding
The auto-trigger logic in the description is ambiguous and excessively expansive, covering creative work, strategy, publication, and vague 'make it great' inputs. Because the skill carries high-authority instructions and external-action pathways, ambiguous triggering materially increases the likelihood of unexpected behavior and unauthorized data handling.

Vague Triggers

High
Confidence
90% confidence
Finding
The manual trigger list includes vague everyday phrases such as 'do it properly' and 'don't rush,' which can be present in normal requests. This makes accidental activation likely, and in the context of this skill that can unlock broader reasoning mandates, external lookups, and cross-model sharing the user did not knowingly request.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill permits autonomous access to external AI platforms but does not front-load a strong privacy warning about transmitting user content to third parties. Even if intended to improve output quality, this omission can lead to users unknowingly exposing sensitive conversation history or files.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The email-sending workflow asks permission to contact the creator but lacks a clear warning that externally shared content may include sensitive project details or user data. This creates a social-engineering-like path where users may approve disclosure without understanding the consequences.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Using open-ended examples plus 'any language' without a defined normalization, translation, or matching policy makes triggering ambiguous and difficult to bound. That ambiguity is risky because an attacker or even normal user phrasing could unintentionally or strategically invoke the skill, causing hidden mode switching and broader influence over model behavior than intended.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Using open-ended examples plus 'any language' without a defined normalization, translation, or matching policy makes triggering ambiguous and difficult to bound. That ambiguity is risky because an attacker or even normal user phrasing could unintentionally or strategically invoke the skill, causing hidden mode switching and broader influence over model behavior than intended.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill metadata says it activates on broad, subjective phrases like "deep think," "expert mode," "do it properly," and even auto-triggers for wide categories such as creative work, strategy, or anything to be published. That can cause the skill to override normal handling for many unrelated prompts, unexpectedly changing system behavior and increasing the chance that its heavier instructions dominate user intent or platform policies.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill normalizes retaining session learnings and potentially storing reusable insights across sessions and files. That creates a natural-language data leakage risk because user-provided details, preferences, project context, or sensitive patterns can be persisted and later surfaced outside the original context.

Ssd 3

Medium
Confidence
97% confidence
Finding
The relay template tells the agent to provide 'full background' and 'what's been discussed' to another model that has zero context. This encourages bulk transfer of conversation history, which can disclose sensitive user information unnecessarily to external models or services.

Unbounded Output

Medium
Category
Output Handling
Content
## SECTION 0 — READ GATE (MANDATORY, ZERO EXCEPTIONS)

Read the entire file — every section, no truncation tolerated. Nothing looks skippable; the section you're tempted to skim is usually the one governing your next mistake.

**Dual mandate, not a contradiction:** Apply protocols exactly as written — precision is the mechanism, not decoration. Simultaneously understand *why* — so behavior is instinct, not compliance theater. Precision without understanding drifts. Understanding without precision misapplies at the edges. Both, always.
Confidence
87% confidence
Finding
no truncation

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
README.md:45

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
SKILL.md:267