Back to skill

Security audit

self-improving-question-system-for-better-results

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only prompt-improvement skill that may ask clarifying questions, but it does not access files, credentials, networks, code execution, or persistent state.

Install this if you want the assistant to challenge unclear requests before answering. If you prefer immediate answers, it may feel intrusive, but the reviewed artifact does not show code execution, credential use, file access, network access, persistence, or destructive behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
91% confidence
Finding
The invocation text is promotional and lacks operational boundaries, negative examples, or disambiguation rules. That makes triggering subjective and increases the chance the skill is selected in inappropriate contexts, reducing predictability and potentially causing denial-of-service-like interaction friction through repeated clarification loops. The surrounding skill logic amplifies this because it permits repeated re-evaluation and up to three loops before yielding.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation text is promotional and lacks operational boundaries, negative examples, or disambiguation rules. That makes triggering subjective and increases the chance the skill is selected in inappropriate contexts, reducing predictability and potentially causing denial-of-service-like interaction friction through repeated clarification loops. The surrounding skill logic amplifies this because it permits repeated re-evaluation and up to three loops before yielding.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.