SQL Query Optimizer

Security checks across malware telemetry and agentic risk

Overview

This skill appears to only review SQL text and suggest optimizations, with no hidden access, persistence, or credential use.

Reasonable to install for SQL tuning help. Review suggested rewrites before running them against a real database, and avoid pasting secrets, credentials, or sensitive production data into SQL examples.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are generic enough that the skill may activate on ordinary conversation about SQL optimization rather than an explicit user request to run this specific skill. Unintended invocation can cause inappropriate processing of user-provided queries, unexpected disclosure of SQL text to the skill, or interference with other safer routing logic.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal