Back to skill

Security audit

agent-workflow-playbook

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow playbook with no executable install behavior, hidden data access, or automatic high-impact actions.

Installers should know the core playbook is mainly written in Chinese, with shorter reference summaries in other languages. Security-wise, it is a passive guide; review any workflow you build from it separately before granting tools that can publish, delete, pay, access private data, or run autonomously.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
This markdown file presents the title and core instructional content in Chinese while other metadata is in English, but it does not state that the skill is intended only for Chinese-speaking users or offer an alternative language option. Under the policy, forcing a language or locale without user opt-in is a natural-language policy concern.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.