content-security-policy

Security checks across malware telemetry and agentic risk

Overview

This appears to be a security/privacy helper with expected automatic checking and redaction behavior, but users should know it may activate broadly and change content.

Install this if you want an agent-level helper that may inspect and redact sensitive content. Review its trigger conditions first, and avoid using it in workflows where automatic rewriting or suppression of content would be disruptive unless you can disable or override it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger conditions are broad phrases like '安全检查', '脱敏处理', and any sensitive operation, which can cause the skill to activate in contexts the user did not intend. In a security-governing skill, ambiguous activation increases the chance of overreach, inconsistent enforcement, or interception of benign requests.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The statement that desensitization may 'automatically trigger while processing user content' is vague and lacks scope, consent, and boundary definitions. Automatic security processing without strict limits can unexpectedly transform data, suppress content, or interfere with other skills and workflows.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal