Back to skill

Security audit

synthesize

Security checks across malware telemetry and agentic risk

Overview

This is a lightweight research-synthesis skill with broad trigger words that may cause accidental activation, but it does not request sensitive access, persistence, or executable behavior.

Install only if you want a report-synthesis helper for multi-channel research results. Be aware that its generic triggers may fire when you use common words like merge or format, so consider narrowing the trigger phrases before publishing or installing widely.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list uses very generic terms ('merge', 'rank', 'format', 'report') that are likely to appear in normal user conversation or other workflows, increasing the chance this skill is invoked unintentionally. Because the skill performs multi-step synthesis and report generation, accidental activation could redirect task flow, consume context, or interfere with more specific skills or built-in behaviors.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
93% confidence
Finding
The skill declares the trigger 'merge', which conflicts with a built-in command name and can shadow or hijack expected command resolution. In practice, users intending to call the built-in command may instead invoke this skill, causing unintended behavior, workflow confusion, or command interception in contexts where merged research reporting is not desired.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
93% confidence
Finding
The trigger 'format' conflicts with a built-in command and is especially risky because it is a highly common verb used across many tasks. This raises the probability of accidental invocation or shadowing, which can disrupt normal command behavior and route user intent into this skill's reporting pipeline instead of the expected formatter.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.