Back to skill

Security audit

Skill with Prompt Engineering by Gen AI Space

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-engineering helper with broad activation wording, but it does not include scripts, credential access, persistence, external actions, or hidden behavior.

Install this if you want a general prompt-writing and skill-drafting assistant. Review the broad trigger wording if you only want narrowly scoped help, since it may activate for many prompt-related requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list is very broad and includes generic requests like creating prompts, improving prompts, designing assistants, and building skills. In a skill-routing environment, this can cause the skill to activate for many unrelated or sensitive prompt-related tasks, increasing the chance it overrides more appropriate safeguards or injects its own workflow into contexts where it does not belong.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal