Back to skill

Security audit

Debug Framework

Security checks across malware telemetry and agentic risk

Overview

This is a frontend debugging workflow skill with no executable code, dependencies, credential use, hidden network behavior, or destructive instructions.

Safe to install for frontend debugging workflows. Be aware it may activate on broad debugging prompts, and review generated diagnostic reports before sharing them because logs, headers, request bodies, or environment details can contain sensitive project information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger list is quite broad and includes common debugging terms in both English and Chinese, which can cause the skill to activate in routine conversations where the user did not actually request this specific diagnostic framework. This is primarily a quality and routing-control issue rather than a direct exploit, but unintended activation can misdirect the agent, reduce relevance, and increase the chance of inappropriate workflow invocation.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description is very broad and includes many generic debugging terms such as 'debug', '异常', and '请求失败', which can cause the skill to be invoked in situations far beyond its intended scope. Overbroad routing increases the chance that this skill intercepts unrelated tasks, leading to incorrect guidance, unnecessary access to troubleshooting context, or unsafe handling of production incident data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.