Back to skill

Security audit

directory-submissions

Security checks across malware telemetry and agentic risk

Overview

This skill is a marketing playbook for directory submissions, with disclosed public-submission workflows and no hidden execution or persistence behavior.

Before using it, be aware that the skill may guide public listings, outreach, review requests, and profile creation. Confirm each submission or public post before the agent acts, and verify directory quality and current platform rules because marketing and SEO details can change.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger description is very broad and includes generic launch, backlink, and listing phrases, which can cause this skill to activate in situations that are only loosely related to directory submissions. Over-broad invocation increases the chance the agent applies specialized SEO/playbook guidance in the wrong context, potentially bypassing a more appropriate skill and causing unwanted actions or irrelevant data gathering.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.