ALab Project Controller

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly disclosed ALab project-administration guide with scoped credential-handling and safety instructions, though it should only be used by users who intend to let an agent manage project state.

Install this only if you want an agent to perform ALab project administration with a project admin key. Keep the key in a private environment variable or secure stdin, review any config, secret, token, or lifecycle changes before applying them, and consider disabling implicit invocation if you want the skill used only after an explicit request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation without any activation constraints, despite being a high-privilege project controller that can create experiments, adjust project configuration, manage lifecycle state, and launch worker sessions. This increases the chance the agent will auto-select and use the skill in loosely related contexts, causing unintended privileged actions or credential-scoped operations without an explicit user decision.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal