Back to skill

Security audit

Data Profiler

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed construction data profiler that reads user-provided datasets and can create local reports, with no evidence of hidden execution or data exfiltration.

Install this if you want an agent to profile construction datasets you provide. Treat generated reports as potentially sensitive because they can include real column names, project identifiers, repeated values, costs, contacts, or other dataset details; store exports only in approved locations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The instruction 'When the user asks to assist with construction project tasks' is overly broad and can cause this skill to activate for many generic construction-related requests rather than only data profiling tasks. That increases the chance the agent applies this skill in unintended contexts, leading to confusing behavior, misuse of file/data handling flows, or accidental overreach beyond the skill's stated purpose.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.