胡田 OPC导师 硅基员工管理

Security checks across malware telemetry and agentic risk

Overview

This is a coherent advisory skill for managing AI-assisted work, with only a minor ambiguity around numbered follow-up links.

Before installing, be aware that replying with a standalone number may navigate to a related skill or follow-up topic. Use explicit requests when possible, and review any generated business, KPI, or revenue guidance before applying it operationally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The follow-up section allows bare-number replies like "1" or "2" to trigger actions without requiring explicit confirmation of scope or target skill. In a multi-skill or multi-turn environment, such ambiguous triggers can cause unintended navigation or invocation, especially when a user sends a standalone number for another purpose.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The referral block instructs users to reply with a bare number to enter a related skill, which creates an ambiguous control surface. This can be exploited by conversational confusion or prompt-injection-style steering to activate adjacent skills the user did not clearly intend to launch.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal