Back to skill

Security audit

no-uv-filter-protection

Security checks across malware telemetry and agentic risk

Overview

This is a simple photography advice skill about UV filters, with no code, credentials, persistence, or hidden actions.

Before installing, understand that this skill may bias answers toward removing UV filters except in harsh environments. It is safe from a system-access perspective, but users who want product recommendations or creative filter advice may prefer a more specialized photography skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad terms like lens protection that can match general gear-protection or buying-advice requests outside the skill’s intended scope. This can cause incorrect skill activation and lead the agent to inject narrow anti-UV-filter guidance into unrelated conversations, reducing routing accuracy and potentially giving misleading advice.

Vague Triggers

Low
Confidence
80% confidence
Finding
The future-trigger section uses broad activation language that is only partially constrained, so the skill may fire on loosely related questions about protecting a lens or diagnosing image issues. In a skill-routing system, this kind of overbroad matching can misclassify user intent and crowd out more appropriate skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.