Skill Design Guide

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill architecture guide with broad but disclosed triggers and no evidence of hidden code execution, credential access, persistence, or data exfiltration.

Installers should know this guide may load for broad skill-design or skill-review language and add architectural advice to the conversation. The reviewed artifact itself is documentation-only and does not run code or access sensitive data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The README advertises broad auto-trigger phrases such as "design a skill," "new agent," and "skill review," which can match normal conversation rather than an intentional request to invoke this skill. In systems that auto-load skills based on keyword matching, this can cause unintended activation, unnecessary context injection, or precedence over a more relevant skill, increasing the risk of prompt-surface expansion and misexecution.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The read_when list contains broad and ambiguous phrases such as '创建新skill', '优化现有skill', and especially 'brain hands session', which could match many normal conversations and cause the skill to load unexpectedly. Overbroad activation increases prompt-surface area and can interfere with more appropriate skills, leading to unintended guidance, context pollution, or policy bypass opportunities through misrouting.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal