Back to skill

Security audit

Sv Analytics Review

Security checks across malware telemetry and agentic risk

Overview

This is a document-only short-video analytics guide with no code, API access, credential handling, or hidden persistence.

Installing this should only add an informational analytics framework; users should be aware it may activate for broad video or content-review prompts, but it does not request accounts, run code, call APIs, or store data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords are broad and generic enough to overlap with common user requests about analytics, performance review, and content improvement. This can cause the skill to activate in situations beyond its intended scope, increasing the chance of unintended invocation and response hijacking relative to more specific skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords include broad generic phrases such as 'content review' and 'improve video' that could match ordinary user requests outside the intended short-video analytics context. This can cause unintended skill invocation, leading to confusing routing, irrelevant responses, or accidental exposure of this skill in contexts where a more appropriate skill should handle the request.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad and generic enough to overlap with ordinary user requests about video performance or content review, which can cause the skill to activate when the user did not specifically intend it. In a routing or auto-invocation system, that can lead to unintended application of this skill's framework and reduce user control, though the skill itself is only descriptive and non-executable.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.