Back to skill

Security audit

Edit

Security checks across malware telemetry and agentic risk

Overview

This is a text-only editing helper whose broad triggers may be imprecise but whose behavior matches its stated purpose.

Install this if you want help editing existing drafts. For vague requests, specify whether you want proofreading, a light edit, shortening, tone adjustment, or a full rewrite, and avoid pasting sensitive text unless you are comfortable sharing it with the host agent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest uses broad trigger phrases like 'make this better', 'clean this up', and general draft-improvement cues, which can cause the skill to activate for a wide range of common user requests. In an agentic system with multiple overlapping skills, this increases the chance of incorrect routing, unintended invocation, and the skill handling content outside its intended editing scope.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.