Back to skill

Security audit

stewardship

Security checks across malware telemetry and agentic risk

Overview

This skill is a markdown-only stewardship guide for plugin quality work, with no hidden execution, credential access, persistence, or data movement.

Install this if you want agents to apply plugin stewardship and quality-review habits. Be aware that its generic triggers may make it appear during some general quality or maintenance discussions, and its advice may nudge the agent to make small nearby cleanup changes unless you ask for a strictly limited edit.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list includes broad, generic terms such as "quality," "culture," and "maintenance" that are likely to appear in many unrelated conversations. This can cause the skill to activate outside its intended context, leading to prompt/context pollution and reducing user trust in skill routing, though it does not by itself enable direct code execution or data exfiltration.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.