Back to skill

Security audit

size probe

Security checks across malware telemetry and agentic risk

Overview

This skill appears low risk because it only contains generic occupational-analysis text, though its scope and packaging are poorly defined.

Before installing, consider that this skill may produce weak or generic occupational-analysis output because its instructions and assets are repetitive and poorly scoped. I found no evidence that it runs code, accesses sensitive data, persists, or modifies the environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Low
Confidence
95% confidence
Finding
The file content is an extremely repetitive, generic description that does not define a clear or narrow activation scope for the skill. Overly broad or vague scope increases the chance the agent may invoke this skill in unintended contexts, which can cause misrouting, confused behavior, or unsafe use of downstream logic even though this file does not itself contain active payloads.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.