Awesome Design Skills

Security checks across malware telemetry and agentic risk

Overview

This skill is a design-skill directory that lists third-party options and install commands, with no evidence of hidden execution, credential access, or destructive behavior.

Use this as a reference guide. Before running any listed git clone command, review the linked repository, prefer a pinned commit or trusted release, and only install skills you explicitly want added to your local agent environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill advertises extremely broad trigger phrases such as general requests for design help, recommendations, and workflow guidance. In an agent-routing context, this can cause the directory skill to activate for many ordinary design requests and steer users toward third-party skills and installation commands, increasing the chance of unintended delegation to unvetted external content.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal