ia-brainstorming

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a brainstorming helper, but it can automatically create and commit repository documents without a clear user approval checkpoint.

Install only if you are comfortable with the agent creating brainstorm files and git commits as part of the workflow. Before using it in an important repository, require the agent to ask before writing files or committing, and review the generated docs/brainstorms changes before they enter project history.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to save a file under docs/brainstorms and commit it to git, but does not require an explicit user confirmation immediately before those repository-modifying actions. In an agentic environment, this can cause unintended persistent changes to the workspace or history, especially if the user expected analysis-only behavior.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
**Path A vs Path B gate.** Routing depends on TWO signals: (1) did any *blocking* question fire before Phase 2.5? AND (2) what tier did Phase 0 classify? Blocking questions = scope disambiguation, dialogue probes, approach selection menus. Internal classification and pressure-tests do not count.

- **Path A** — Lightweight tier AND no blocking questions fired → announce-mode. Emit "What we're building" prose only (no other sections, no confirmation question), then proceed to Phase 3 doc-write in the same turn. Lightweight Path A docs are short; post-hoc revision is cheap.
- **Path B** — Standard/Deep tier OR any blocking question fired → full synthesis with confirmation gate. Two scenarios fire Path B: the user invested answer-time in dialogue, or pre-loaded substantive scope content. Either way, the substance earns a real checkpoint. The tier guard catches pre-loaded Deep brainstorms that would otherwise shortcut via the no-questions branch.

**Keep tests per section.** Each conditional section has its own keep test; failing items dissolve into the internal draft only.
Confidence
87% confidence
Finding
no confirmation

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal