Nm Attune Project Planning

Security checks across malware telemetry and agentic risk

Overview

This planning skill is mostly transparent, but it tells the agent to automatically move from planning into execution without asking the user first.

Install only if you are comfortable with the planning workflow automatically continuing into execution. To keep it planning-only, use the documented `--standalone` flag or explicitly tell the agent to stop after producing the plan.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly requires automatic invocation of the next phase (`project-execution`) after saving the implementation plan, and it instructs the agent not to seek user confirmation. This creates an unsafe control-flow transition from a planning-only skill into an execution-capable skill, increasing the chance of unintended actions being taken beyond the user's original scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal