Back to plugin

Security audit

Evidencecraft

Security checks across malware telemetry and agentic risk

Overview

Evidencecraft is a disclosed skills-only reporting workflow that reads and writes workspace Markdown artifacts for planning, evidence logging, execution, and review, with user-controlled execution gates.

Before installing, expect the agent to read relevant workspace files and create or update Evidencecraft Markdown artifacts such as briefs, plans, run logs, evidence logs, reviews, and final reports. Review generated Plans, output paths, and execution-mode choices carefully when the workspace contains sensitive or high-impact data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
Ignore incidental foreign terms, links, citations, code, and quoted source titles when detecting the request's primary language. A Simplified Chinese request defaults to Simplified Chinese.

Infer without asking when the rules yield one answer. If two explicit current requirements conflict, ask one focused question in the primary language of the request and stop the affected transition until resolved.

## Respect lifecycle ownership
Confidence
22% confidence
Finding
without asking

Hidden Instructions

High
Category
Prompt Injection
Content
## Unsupported, blocked, and conflicting items

<!-- Template instruction: keep these visible even when excluded from the draft. -->

| Item | Attempted evidence or conflict | Why unresolved | Affected output | Return Route or reader disclosure |
|---|---|---|---|---|
Confidence
87% confidence
Finding
<!-- Template instruction: keep these visible even when excluded from the draft. -->

Hidden Instructions

High
Category
Prompt Injection
Content
## Findings

<!-- Template instruction: repeat for every finding; if none, state the artifact-language equivalent of `No findings`. -->

### RV-<id>: <title>
Confidence
88% confidence
Finding
<!-- Template instruction: repeat for every finding; if none, state the artifact-language equivalent of `No findings`. -->

Hidden Instructions

High
Category
Prompt Injection
Content
# Evidence Log

<!-- Template instruction: instantiate this internal governance log in the run workspace; use one card per source slice, upstream artifact, or distinct evidentiary basis. A file name alone is not traceability. Evidence IDs and internal paths do not belong in the standalone reader report. -->

## Log identity
Confidence
90% confidence
Finding
<!-- Template instruction: instantiate this internal governance log in the run workspace; use one card per source slice, upstream artifact, or distinct evidentiary basis. A file name alone is not trac

Hidden Instructions

High
Category
Prompt Injection
Content
<!-- Template use: render every heading, label, table header, placeholder replacement, and narrative passage in the confirmed artifact language. The sample title's “Analysis Review Report” phrase is a translatable artifact-type label, not a canonical identifier. Preserve canonical verdict/status codes and IDs, exact Skill names, paths, hashes, citations, code, formulas, and original source titles. Remove this and every Template instruction comment from the instantiated artifact. -->

# Analysis Review Report
Confidence
90% confidence
Finding
<!-- Template use: render every heading, label, table header, placeholder replacement, and narrative passage in the confirmed artifact language. The sample title's “Analysis Review Report” phrase is a

Hidden Instructions

High
Category
Prompt Injection
Content
<!-- Template use: render every heading, label, table header, placeholder replacement, and narrative passage in the confirmed artifact language. The sample title's “Evidence Log” phrase is a translatable artifact-type label, not a canonical identifier. Preserve canonical codes and IDs, exact Skill names, paths, hashes, citations, code, formulas, and original source titles. Remove this and every Template instruction comment from the instantiated artifact. -->

# Evidence Log
Confidence
92% confidence
Finding
<!-- Template use: render every heading, label, table header, placeholder replacement, and narrative passage in the confirmed artifact language. The sample title's “Evidence Log” phrase is a translata

Hidden Instructions

High
Category
Prompt Injection
Content
## Main Agent verification

<!-- Template instruction: complete after receiving the independent report; do not let the reviewer fill this section. -->

- Material findings checked against actual artifacts:
- Feedback reclassified or rejected with counter-evidence:
Confidence
92% confidence
Finding
<!-- Template instruction: complete after receiving the independent report; do not let the reviewer fill this section. -->

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt says to use this skill 'after this Run explicitly selects Inline Execution,' but it does not define a precise, machine-verifiable trigger or boundary for activation. In agent workflows, ambiguous activation conditions can cause the skill to run in the wrong context, potentially executing report steps or preparing outputs before prerequisite review and authorization checks are complete.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to 'read and apply the shared language contract' for questions and revised profiles, which can force user-visible output into a prescribed artifact language without explicit user choice. This creates a policy and safety issue because it can override the user's requested language or reduce clarity in a sensitive analytical workflow, increasing the chance of misunderstanding or unusable deliverables.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The completion gate makes artifact-language output a requirement for successful completion, which pressures the agent to prioritize localization compliance over user intent or comprehension. Because completion criteria are strong behavioral constraints, this can systematically produce outputs in an undesired language and propagate confusion into later planning and review stages.

Natural-Language Policy Violations

Medium
Confidence
98% confidence
Finding
This section mandates that every user-visible part of the Source Profile be rendered in the artifact language, with no opt-out or fallback path. In practice, that can cause the agent to ignore user preference, team operating language, or accessibility needs, which is especially risky because this skill produces documentation relied on by downstream analysis and review.

VirusTotal

64/64 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
skills/subagent-driven-reporting/assets/subagent-progress-template.md:13
Evidence
- Explicit parallel authorization: `[REDACTED]`