Team Communication

Security checks across malware telemetry and agentic risk

Overview

This is a text-only team messaging guide; its main risk is accidentally sharing sensitive information with another agent session.

Install only if you want the agent to coordinate with the listed team sessions. Verify the sessionKey before sending, and avoid sending secrets, credentials, private customer data, or full conversation history unless the recipient is trusted and authorized.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description uses very broad activation phrasing around internal communication, coordination, help requests, and messaging. In an agentic system, this can cause the skill to trigger for many ordinary user intents, unnecessarily exposing messaging capabilities and increasing the chance of unintended cross-agent actions or information sharing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal