Charts

Security checks across malware telemetry and agentic risk

Overview

This is a simple chart-generation skill with disclosed output behavior and no executable code or hidden access.

Safe to install for normal chart creation. Be aware that broad trigger words may activate it when discussing charts generally, and avoid placing sensitive data in generated charts unless saving it under /workspace/reports/charts/ is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases include very generic terms like "图表" and "charts", which are likely to appear in normal user conversation and can cause unintended skill activation. In an agent environment, overly broad triggers can route unrelated requests into this skill, leading to incorrect behavior, confusion, or unexpected file/output generation under `/workspace/reports/charts/`.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal