Back to skill

Security audit

Cynefin

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only decision-coaching skill with examples and no code, install scripts, credential handling, or persistence.

Safe to install as a decision-support skill. Treat its crisis and business examples as advisory framing, and keep normal user confirmation for any real operational actions outside the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
- A familiar approach has stopped working and you can't articulate why
- Experts disagree on the right answer — a crisis unfolding where the previous playbook doesn't apply
- "Best practices from X" imported without checking if the domain matches
- A team is over-planning something emergent, or "let's get more data" when data won't come without action
- Allocating AI capex or racing AI-native competition: deciding which AI bets are engineering (Complicated), emergent agent/adoption experiments (Complex), or live incidents (Chaotic)
Confidence
75% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.