Before You Build Skill

Security checks across malware telemetry and agentic risk

Overview

This is a text-only product risk review skill with a clearly disclosed optional external case lookup and no executable payload.

Reasonable to install if you want an agent to challenge product or feature ideas before coding. Be aware it may activate too readily on generic feature-planning prompts, and only approve the optional Case Memory lookup when you are comfortable sending a short non-confidential idea summary to beforeyoubuild.fyi.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger examples include broad phrases such as "Should I add this feature?" and "Competitors have X. Should we add it?" that could match normal product or planning conversations and cause the skill to activate outside its intended niche. Unintended invocation is dangerous because it can override a more appropriate skill or workflow, leading to misrouting, unnecessary external case-memory prompts, and user confusion in contexts where this skeptical pre-build framing is not suitable.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal