Specification Extractor

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a straightforward construction-specification PDF extractor with no evidence of hidden network access, credential use, persistence, or destructive behavior.

Install only if you are comfortable letting the skill read the project specification files you explicitly provide. Use clear file paths, avoid giving it unrelated private documents, and review any exported CSV, Excel, JSON, or report output before sharing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The phrase 'When the user asks to convert or extract data' is very broad and does not define what kinds of data, documents, or contexts should trigger this skill. Without narrower trigger scope or exclusion examples, it risks unintended activation for common requests outside construction specifications.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal