Back to skill

Security audit

diff-analysis

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed diff-analysis guidance skill with no hidden execution, persistence, or destructive behavior in the inspected artifacts.

This skill is reasonable to install for structured diff and release-note work. Be aware that broad trigger words may cause it to load during generic change-summary conversations, and review any separate Night Market or Claude Code plugin before enabling agents, hooks, or commands beyond this markdown skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list includes very generic terms such as "changes," "summaries," and "risk-assessment," which are likely to appear in many unrelated conversations. In an agent environment, that broad matching can cause unintended skill activation, pulling in workflows and external integrations when the user did not explicitly request this skill.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The auto-load guidance says to load when "Git diffs present, change analysis requested, impact assessment needed," which is underspecified and overlaps with many normal development tasks. Because the skill also directs integration with other tools and modules, ambiguous activation increases the chance of unnecessary execution paths and context expansion.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.