Back to skill

Security audit

ALab Skills

Security checks across malware telemetry and agentic risk

Overview

This is a coherent ALab workflow skill bundle with disclosed root, project, and experiment roles, but users should be careful because it can guide credentialed administrative work.

Install only if you intend to use ALab and trust the alab-cli package source. Keep root and project admin keys out of prompts and logs, prefer stdin or ignored secret files, and use the narrowest ALab role skill for the task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation for a top-level routing capability without any visible trigger constraints or exclusion conditions. That increases the chance the platform auto-selects this skill in unintended contexts, which can silently influence tool/skill routing and potentially steer work toward privileged subskills or credentialed operations beyond the user's intended scope.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill combines a very broad default prompt with allow_implicit_invocation: true, which can cause the agent to auto-trigger this worker in situations that only loosely match the description. Because the skill is empowered to inspect prior evidence, modify experiment worktrees, run evaluations, and submit results, ambiguous invocation conditions increase the chance of unintended execution or premature submission actions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
This skill enables implicit invocation for a root-admin role without any visible trigger constraints or gating conditions. In agentic systems, ambiguous auto-activation of a privileged skill increases the chance that unrelated user requests, prompt injection, or planner mistakes cause administrative capabilities to be loaded and used unintentionally.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The manifest advertises administration of ALab homes and root operations but does not warn the user or orchestrator that these actions can affect system-wide resources. Missing safety signaling around privileged operations makes accidental misuse more likely and reduces the chance that higher-level controls will require confirmation or least-privilege handling.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation with no visible activation constraints, so it may be triggered in broader contexts than intended. Because this is a project-controller skill that can create experiments, launch worker sessions, and summarize run evidence, over-broad triggering increases the chance of unintended orchestration actions or context leakage through accidental or adversarial invocation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.