Bluefocus Model Routing

Security checks across malware telemetry and agentic risk

Overview

The available evidence shows a low-risk routing/help skill with overly broad activation wording, not hidden or harmful behavior.

Reasonable to install if you want model-routing or execution-optimization guidance. Review the trigger wording before relying on it automatically, because broad phrases like cost saving or speed optimization may cause the skill to activate when you only intended a general discussion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list is unusually broad and includes generic phrases such as model selection, cost saving, and speed optimization that can appear in ordinary user conversations. This can cause the skill to activate unintentionally in unrelated contexts, influencing routing or workflow decisions when the user did not explicitly request this skill, which is a prompt-scope and behavior-integrity risk rather than direct code execution.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal