Response Timing

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill helps an agent decide when to reply in group chats and does not add code, data access, credentials, or persistence.

Install this if you want an agent to be quieter in group chats and mainly respond when mentioned, named, or clearly responsible for the task. Users should address the agent explicitly in ambiguous conversations to avoid missed or unintended replies.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The rule allowing replies when a task is 'obviously' owned by the agent is underspecified and can cause the agent to answer in group chats without an explicit mention. In a response-timing skill, ambiguous activation logic is security-relevant because it can lead to unintended participation, leakage of context, or disruption of other agents' workflows.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The emergency exception permits proactive replies even without the agent being addressed, based only on broad urgency cues like '紧急' or 'ASAP'. This can be exploited to trigger unsolicited responses in group settings, causing the agent to interject into conversations, potentially reveal capabilities or context, and undermine role boundaries.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal