Back to skill

Security audit

North Star Metric

Security checks across malware telemetry and agentic risk

Overview

This is a benign strategy-coaching skill, with only a minor risk that its broad trigger phrase could activate it in some unrelated optimization discussions.

Safe to install for product strategy or metrics work. Be aware it may be invoked by generic optimization questions, so users should confirm they actually want North Star Metric guidance in those cases.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
In the activation description, the skill can trigger when someone asks "what should we optimize?" That phrase is common in many business and product discussions and is not specific to north-star-metric selection, which increases the risk of unintended invocation despite the surrounding examples.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The markdown states the skill should be used when someone says "what should we optimize," which is an ambiguous phrase that overlaps with routine prioritization conversations. Although the file includes some exclusion conditions, this specific trigger remains broad enough to cause accidental activation outside NSM use cases.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.