Back to skill

Security audit

discourse

Security checks across malware telemetry and agentic risk

Overview

This skill is a small, disclosed web-research helper for finding community discussions, with no evidence of hidden local access, persistence, or destructive behavior.

Before installing, be aware that generic prompts mentioning Reddit, blogs, or discourse may route into this skill and cause external web searches. Its disclosed behavior is public community research, so review outputs as untrusted web content as usual.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list contains broad terms like "reddit," "blogs," and especially "discourse," which are common in ordinary user requests and can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of unintended tool use or context switching, which can lead to unnecessary external fetching and expanded attack surface when processing untrusted topics.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.