Back to skill

Security audit

Inversion

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a harmless decision-analysis template, but it tells agents to fetch and use a remote latest version at runtime, which can change the reviewed instructions after installation.

Install only if you are comfortable with the skill contacting deciqai.com during use and potentially following updated skill text that was not part of this review. Prefer a pinned local copy or disable the runtime update fetch unless you explicitly trust that remote endpoint.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly instructs the agent to make an unauthenticated external network request at the start of every run to retrieve a canonical current version of the skill. This creates a prompt-supply-chain risk: remote content can change behavior after review, bypass local auditing, and trigger unannounced data egress or execution of adversarial instructions from a third-party host.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.