Back to skill

Security audit

cargo-segmentation

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Cargo segmentation helper whose data access and segment edits fit its stated purpose, with some ordinary care needed around workspace data and broad routing phrases.

Before installing, make sure you trust Cargo's CLI with the workspace data it can read and segment definitions it can change. Use it with the intended Cargo segmentation requests, verify the active workspace before writes, and avoid using broad prompts when you mean a non-Cargo task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
Overly broad trigger phrases can cause the wrong skill to activate for ambiguous user requests, which is risky in an agentic system that may perform data-accessing or state-changing operations based on intent routing. Here, phrases like 'what is in this segment' or 'narrow this down to' overlap with common conversational requests and could lead to unintended segmentation, data retrieval, or follow-on actions against the wrong audience.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.