Back to skill

Security audit

My New Skill

Security checks across malware telemetry and agentic risk

Overview

This appears to be an unfinished template skill, not a harmful one.

Before installing, treat this as an unfinished starter template rather than a useful skill. It should be completed with a clear purpose, trigger conditions, and workflow before practical use, but the reviewed evidence does not show malicious code or sensitive access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The skill metadata leaves the description and trigger conditions as TODO placeholders, so the agent has no clear boundaries for when this skill should activate. Ambiguous activation guidance can cause the skill to be invoked in unintended contexts, increasing the chance of incorrect behavior or misuse, though this template itself does not contain directly dangerous actions.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The main body is still template text rather than operational guidance, which means the skill's behavior, scope, and expected workflow are undefined. This can lead to inconsistent or overly broad use by an agent, creating reliability and policy-enforcement risks even if there is no explicit malicious payload in the file.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.