Fact Check

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only fact-checking skill whose tool and network checks are disclosed and aligned with verifying claims.

Install if you want an agent to be more rigorous about checking factual and technical claims. Expect it to run verification commands or make limited network/API checks when claims need confirmation, and be cautious when using it around private repositories, confidential URLs, or authenticated GitHub/API sessions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation condition is overly broad because it triggers on very common content such as version numbers, dates, API references, and model names. In practice this can cause unnecessary invocation of the skill in many unrelated contexts, increasing the chance of needless external checks, tool usage, and user friction; in an agentic system, broad activation can also expand the attack surface by causing the skill to run on adversarially crafted text.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal