Back to skill

Security audit

catchup

Security checks across malware telemetry and agentic risk

Overview

This skill is a transparent catch-up workflow that summarizes recent work using user-directed repository, document, or log context.

Before installing, be aware that generic requests for status or summaries may invoke this skill; use it when you want catch-up analysis over a specific repository, document set, sprint, or log window, and keep sensitive logs or private documents out of scope unless you intend them to be summarized.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The listed activation terms include generic words like "summary," "status," "progress," and "context," along with cues such as "get me up to speed" and "current status." These phrases are common in ordinary conversation and could trigger the skill in situations far beyond the intended catch-up workflow, especially since no narrow scope or exclusion conditions are provided here.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.