Nm Leyline Stewardship

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only stewardship guide for plugin maintenance, with no executable code, credential access, or hidden runtime behavior.

Safe to install as a lightweight development-practice guide. Review generated diffs because it encourages small opportunistic improvements, and be cautious with local quality commands in repositories you do not trust.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list contains several broad, generic terms such as "quality," "culture," "maintenance," and "character," which can cause the skill to activate in contexts unrelated to this specific stewardship plugin. Unintended activation can inject irrelevant guidance into unrelated tasks, reducing reliability and potentially interfering with higher-priority or security-sensitive workflows.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal