Back to skill

Security audit

Prompt Engineer

Security checks across malware telemetry and agentic risk

Overview

This appears to be a prompt-generation skill with minor usability risks around broad triggering and default language, but no evidence of hidden access, persistence, credential use, or unsafe actions.

Installers should expect this skill to help create or refine prompts. Review its trigger wording and language defaults if you work in English or a multilingual environment, and invoke it explicitly for prompt-engineering tasks to avoid accidental use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The initialization text invites users to provide nearly any task ('tell me what task you want AI to complete'), making activation overlap with broad everyday requests. In agent environments, overly broad trigger language can cause this skill to activate unintentionally and take over benign conversations, increasing prompt-scope confusion and the chance of misrouting or instruction interference.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
Defaulting output to Simplified Chinese without explicit user opt-in can override user expectations and upstream system preferences, creating language-control conflicts in multi-skill or multilingual environments. This is especially risky for prompt-generation skills because the produced prompt may become unusable, misunderstood, or incorrectly routed if the surrounding workflow expects another language.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.