Back to skill

Security audit

Manager Development Spectrum

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a coaching/diagnostic prompt skill with a broad trigger, but there is no evidence of malware, hidden execution, credential use, persistence, or data exfiltration.

Install only if you want the agent to apply a developmental or leadership coaching lens. If it activates in routine HR, performance, or mental-health-sensitive conversations, treat its output as optional framing and ask the agent to use a narrower workplace, HR, or support approach instead.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation criteria use several broad natural-language triggers such as 'leadership training isn't working' and 'why can't I get to the next level,' which can match ordinary workplace or coaching conversations outside the narrow intended use case. In an agentic system, this can cause over-activation of the skill, leading the agent to apply a developmental-stage diagnostic framework where a simpler performance, training, or HR response would be more appropriate.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.