Back to skill

Security audit

Challenge Loop

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a review/challenge helper, but its broad triggers and self-starting review behavior could alter agent responses or spawn challenger review without clear user intent.

Install only if you want the agent to add critical-review behavior and possibly use challenger subagents. Prefer using it with explicit commands, and watch for unwanted activation on ordinary review or doubt-checking phrases; the publisher should narrow triggers and define when autonomous activation is allowed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The inline trigger list includes broad conversational phrases such as "any issues?" and similar Chinese equivalents, which are likely to appear in ordinary user requests rather than as an explicit request to invoke this skill. Because this skill alters response behavior by injecting a self-refutation block, accidental activation can change outputs unexpectedly and create prompt-routing ambiguity across unrelated tasks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The subagent mode is activated by generic review phrases like "review this" and "challenge this," which commonly occur in normal collaboration. In this skill, those phrases can cause spawning of an independent challenger subagent, increasing execution scope, cost, latency, and the chance of unintended delegation from benign conversation.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes broad conversational phrases such as '再想想', '靠谱吗', and '有没有漏洞' that can naturally appear in ordinary user dialogue, making unintended activation plausible. Because this skill changes response behavior and can invoke subagent review loops, accidental triggering can increase latency, cost, and output drift without clear user intent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The rule allowing the agent to self-initiate when output is 'high-risk' lacks a precise definition, so the skill can activate unpredictably based on subjective model judgment. In a system that can spawn subagents and alter final outputs, ambiguous autonomous activation expands behavior beyond explicit user consent and can be abused or misfire in sensitive contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.