鲁班 | Luban 打磨工坊

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only workflow for improving and publishing skills, with disclosed research and editing behavior that users should keep under explicit control.

Install this if you want an opinionated assistant workflow for making a skill clearer, more testable, and easier to publish. Use it carefully on private repositories: ask for offline-only review when needed, confirm before network research, and require explicit approval before commits, pushes, releases, or deployments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger scope is very broad and matches generic requests like improving, optimizing, auditing, or publishing a skill. This can cause unintended invocation on adjacent tasks, leading the agent to perform extensive repository inspection, network research, and modification-oriented behavior when the user may have only wanted a narrow review.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal