Nm Archetypes Architecture Paradigm Client Server

Security checks across malware telemetry and agentic risk

Overview

This appears to be a benign advisory skill whose main issue is broad activation wording, not malicious behavior.

Reasonable to install if you want architecture or distributed-systems guidance. Expect possible over-activation from broad trigger phrases; invoke it explicitly for relevant design or trust-boundary work and disable or narrow it if it interferes with unrelated tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger list includes broad phrases such as "architecture," "distributed-systems," and "trust boundaries," which are likely to activate the skill in many unrelated contexts. Overbroad auto-activation can cause the wrong skill to influence agent behavior, leading to scope confusion, lower-quality guidance, and increased exposure to prompt-injection or unsafe instruction blending from unintended contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal