Nm Abstract Methodology Curator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only methodology skill with one minor overbroad-trigger concern but no evidence of hidden access, persistence, credential handling, or unsafe execution.

Installers should know this skill may activate in some general design or evaluation conversations. That is a usability/scoping concern, not a security concern in the reviewed artifacts; review the methodology it suggests before allowing it to shape important work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger list includes very broad, everyday terms such as "design," "evaluation," and "or agents," which can cause the skill to activate in many unrelated contexts. Over-broad invocation increases the chance that this skill intercepts prompts outside its intended scope, creating prompt-routing confusion and potentially influencing tasks involving skill or agent creation where methodological guidance was not requested.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal