Back to skill

Security audit

Extenics Innovation Method

Security checks across malware telemetry and agentic risk

Overview

This is a structured innovation-method guide with no executable behavior or hidden data access; its main caveat is that it may activate broadly for innovation-related requests.

Install this if you want innovation and product-development questions handled through a structured IASE/TRIZ/Extenics framework. For generic brainstorming or a different language, state that preference explicitly because the skill's trigger wording and templates are broad and Chinese-oriented.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation description contains a very broad set of trigger intents spanning general innovation, product development, patent work, evaluation, and creative thinking, without meaningful exclusions or routing constraints. This can cause the skill to activate outside its intended scope, overriding more appropriate skills or injecting a rigid methodology into unrelated requests, which is a prompt-routing and behavior-integrity risk.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill content is written to enforce Chinese-language behavior across the skill without offering user choice or stating a justified locale requirement. This can create misalignment with user expectations, reduce transparency, and in multilingual systems may be used to steer output formatting or comprehension in ways the user did not request, though the security impact is limited.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.