Concept Validation

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable advisory skill for planning and operating concept validation centers, with no evidence of hidden data access, persistence, or harmful behavior.

This skill is reasonable to install for concept validation center planning. Users should still treat policy, investment, IP, and compliance advice as advisory, verify current official requirements, and avoid sharing confidential project or investor details with linked skills unless those tools are trusted and appropriate.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keywords are overly broad and include common terms such as funding, team, management, plan, and risk. In a multi-skill routing environment, this can cause the skill to activate for generic conversations outside its intended scope, leading to misrouting, irrelevant guidance, and possible unintended transfer of user context to linked skills.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal