Back to skill

Security audit

Loop Stability Check

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable workflow-analysis skill that may auto-apply a loop-diagnosis format, but it does not request data, credentials, commands, or external access.

Install this if you want an agent to use a structured format for diagnosing stuck or unstable workflows. Be aware it can be invoked implicitly and may impose its loop-analysis template when the agent thinks a task is not converging, so review its recommendations before applying them to important operations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation triggers are broad, qualitative descriptions with no explicit exclusion criteria, priority rules, or scope limits. That can cause the skill to be invoked in situations where it does not fit, leading to overly rigid loop-focused handling, misclassification of normal iteration as instability, and degraded decision-making in adjacent workflows.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill enables implicit invocation with no visible trigger constraints, exclusions, or scope limits. That can cause the agent to invoke this skill unexpectedly in unrelated contexts, increasing the risk of prompt-routing errors, workflow disruption, and unnecessary execution loops—especially for a skill specifically designed to inspect loop stability and control retry behavior.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal