Back to skill

Security audit

DemandSpec

Security checks across malware telemetry and agentic risk

Overview

DemandSpec is a disclosed requirements-documentation skill that writes structured project artifacts, with no evidence of hidden data access, persistence, exfiltration, or destructive behavior.

Use this skill when you want an agent to turn product or workflow material into local requirements documents. Before running it in an important repository, review the target paths and be explicit if you only want discussion or a draft in chat, because the skill is designed to create or update workspace files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is very broad and can trigger on many ordinary product, planning, or requirements conversations. Overbroad activation increases the chance the agent invokes a file-writing workflow in situations where the user only wanted discussion or light guidance, creating unnecessary side effects and expanding the attack surface for prompt-injection via unrelated documents in the workspace.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill repeatedly instructs the agent to create and write files in the workspace, and even says not to only reply in chat, but it does not require explicit user consent immediately before making local modifications. In a real agent environment, this can cause unintended file creation or overwrite, especially when the skill is auto-invoked from ambiguous conversations or when existing repository content is adversarially crafted to steer where files are written.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.