Back to skill

Security audit

perception-design-system

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only UX design methodology skill with no executable behavior, data access, persistence, or hidden authority.

Before installing, note that this skill is broad UX guidance rather than a domain compliance framework. For financial, health, security, or regulated workflows, treat it as design input only and still rely on appropriate legal, safety, accessibility, and product review. Also note the CC-BY-NC-4.0 license limits commercial use without authorization.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill declares applicability to both highly specialized domains like finance/security and effectively 'any software product,' which makes invocation scope overly broad and ambiguous. In agent environments, this can cause the skill to be selected in contexts where its design guidance is irrelevant or inappropriate, increasing the chance of poor decisions or unsafe UX recommendations in sensitive workflows.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.