Back to skill

Security audit

triz

Security checks across malware telemetry and agentic risk

Overview

This skill is a small TRIZ brainstorming aid with no executable code, persistence, credential use, or hidden data access.

Before installing, be aware that generic prompts about innovation or analogy may activate this skill even when you did not specifically ask for TRIZ. The inspected package itself is only guidance text and does not add code execution, credential access, or persistence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes broad, generic phrases such as "innovation," "analogy," and especially the natural-language phrase about being "stuck on a problem," which can match many unrelated user requests. Overbroad activation increases the chance this skill is invoked unintentionally, causing context hijacking or irrelevant guidance to be inserted into workflows where it was not requested.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.