DemandSpec

Security checks across malware telemetry and agentic risk

Overview

DemandSpec is a coherent requirements-documentation skill with no evidence of hidden execution, credential access, exfiltration, or destructive behavior.

Use this skill when you want structured PRDs, acceptance criteria, review checklists, and development handoff documents. Confirm the output language and destination folder, and review generated requirements before treating them as approved business or engineering direction.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The manifest description is broad enough to activate on many ordinary requirement- or product-related conversations, which can cause the skill to trigger outside its intended scope. Over-broad activation increases the chance that users are steered into this workflow when they did not request it, potentially causing unwanted file generation, process hijacking, or inappropriate instruction injection into unrelated tasks.

Natural-Language Policy Violations

Medium
Confidence
73% confidence
Finding
The skill content strongly centers Chinese output and does not provide a user-language negotiation path, which can cause responses in a language the user did not request or cannot verify. In a requirements-engineering context, this can lead to misunderstanding, review failure, and accidental approval of incorrect specifications, though it is less severe than direct code-execution or data-exfiltration issues.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal