Back to skill

Security audit

Session Branch

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed session-handoff helper that writes a project handoff file and only accesses sensitive IDE memory or identity files with explicit consent.

Before installing, understand that this skill can create or overwrite a handoff document in your project containing sanitized summaries of your session. Review the generated handoff before sharing or committing it, and only approve optional IDE memory or identity scans if you are comfortable exposing that local context to the active agent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The documented trigger phrases include short, natural conversational terms like “分叉” and “开个支线”, which can plausibly appear in ordinary discussion and may activate the skill unintentionally. Because this skill writes or overwrites a handoff file in the project, accidental activation can cause unintended file creation, disclosure of summarized project context into a durable document, or workflow disruption.

Vague Triggers

Low
Confidence
72% confidence
Finding
The English usage section tells users to invoke the skill using untranslated Chinese trigger phrases without clearly stating that activation is limited to those exact phrases. This ambiguity increases the chance that users misunderstand when the skill may fire, making accidental invocation or misuse more likely, though the risk is somewhat reduced because the triggers are still specific Chinese phrases.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.