Data Analysis Workflow

Security checks across malware telemetry and agentic risk

Overview

This is a local data-analysis workflow that reads user-provided datasets and prints summaries, with no evidence of hidden access, persistence, network transfer, or destructive behavior.

Before installing, be aware that the skill may trigger on general data-analysis prompts. Run it only on datasets you intend to inspect locally, because it prints dataset structure and summary statistics to the console.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords are broad generic terms like 'data analysis' and 'statistical analysis', which can cause this workflow skill to activate for ordinary user requests that did not intend to invoke a multi-stage workflow. This increases the chance of unintended routing, overbroad capability invocation, and confusing or inappropriate responses, especially because the skill aggregates multiple downstream analysis capabilities.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal