Back to skill

Security audit

architecture-paradigm-serverless

Security checks across malware telemetry and agentic risk

Overview

This skill is a plain serverless architecture guidance document with no code execution, credential access, persistence, or hidden behavior.

Install only if you want general serverless architecture advice available in design discussions. Be aware it may trigger on broad architecture topics, so users should confirm serverless is actually relevant before following its recommendations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list contains very broad terms such as 'architecture', 'serverless', and 'event-driven', which can cause this skill to activate in many general design conversations rather than only in narrowly scoped serverless requests. In an agent environment, over-broad activation can steer users into an unintended workflow, increase prompt-surface exposure, and crowd out more appropriate skills, though this file does not contain overtly malicious behavior.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.