Back to skill

Security audit

TalonForge Safety Rails (EN/AR)

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed safety-configuration guide with no executable payload, though users should review the extra tools it suggests installing.

Before installing, review the generated safety rules and only allow the suggested extra tools if you trust those packages too. Prefer explicitly asking the agent to configure safety rails for the current workspace and confirm any changes before applying them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrase "Set up safety rails" is broad and underspecified, which can cause the agent to apply this skill in contexts beyond the user's intent. Because the skill changes trust, approval, and communication policies, an overly generic activation phrase increases the chance of unintended security-relevant reconfiguration or misuse by indirect prompting.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.