Back to skill

Security audit

Map Is Not the Territory

Security checks across malware telemetry and agentic risk

Overview

This is a reflective decision-making coaching skill with no executable code, credential access, persistence, or hidden high-impact behavior.

This skill is appropriate if you want an agent to challenge stale metrics, models, plans, or assumptions. It may make strategic recommendations such as updating or replacing a model, but those are advisory outputs rather than automatic actions, so review any consequential business decision yourself before acting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
- Team disagreement cannot be resolved by data — parties are disagreeing about maps, not territory
- A strategy, model, process, or org chart has not been reviewed in more than one planning cycle
- "The data shows..." but the data is old, narrow, or from a proxy source
- A metric is being optimized directly without asking whether it still maps to the underlying goal
- An AI model's benchmark score, leaderboard rank, or internal "world model" is being treated as proof of real-world capability (AI adoption / AI hype)

**Not when:** the map is demonstrably current and well-calibrated; decision is low-stakes; territory is stable and map is freshly validated.
Confidence
75% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.