Back to skill

Security audit

TRPG Abbreviation Check (Briefing)

Security checks across malware telemetry and agentic risk

Overview

This skill is a focused TRPG document-editing helper, but users should be aware it encourages broad batch edits across briefing and related rule files.

Install this only if you want an agent to make broad abbreviation fixes in TRPG briefing and related rule documents. When using it, specify the exact folder or files to edit and review the resulting diff before accepting changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to read many files at once, perform bulk abbreviation replacements, and write all files back simultaneously, but it provides no requirement to warn the user, preview changes, confirm scope, or create a reversible patch. In an agent setting this can cause broad, unintended modification of project files outside the user's expected target set, including non-briefing files, with errors propagating across many documents at once.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.