Lab2startup Challenge Solutions

Security checks across malware telemetry and agentic risk

Overview

This is a text-only advisory skill for teacher-student startup collaboration challenges and does not request code execution, credentials, local data, or system changes.

This appears safe to install from a security perspective. Users should treat its governance, IP, equity, and commercialization advice as general planning guidance, and avoid sharing confidential project details unless they are comfortable giving them to the agent using the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description uses many broad trigger terms such as '技术落地', '技术转化', and '产品化' without clear boundaries, which can cause the agent to invoke this skill in loosely related conversations. Overbroad activation is a real security and quality issue because it increases unintended routing, causing irrelevant guidance to override more appropriate skills or leak domain influence into unrelated contexts.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal