Back to skill

Security audit

User Insight Engine

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only user research skill with disclosed coaching instructions and no evidence of hidden execution, credential use, persistence, or destructive behavior.

Before installing, understand that the skill may guide product or research decisions using user behavior data, so users should apply normal review before acting on its suggested interventions. It does not request system access or automatic execution authority.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
## Red Flags

- Behavioral and survey data presented together without checking for Surface–Behavioral conflicts
- "User research" = interviews only; no behavioral layer
- No Deep Layer evidence ever collected for this behavior
- Interventions designed before a driver has been identified
Confidence
75% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.