Virtual Reading Group

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed academic reading-group workflow that reads user-selected papers and writes markdown notes, with no evidence of hidden or harmful behavior.

Install only if you want a multi-agent reading-group workflow rather than a simple paper summary. Use a fresh output folder for each run, avoid placing unrelated private files in that folder, and review intermediate notes/citations before relying on the final synthesis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says the skill triggers on requests to "analyze academic literature" or "synthesize research across multiple sources," which are broad phrases that can overlap with many ordinary research-assistance requests. The file does not provide narrowing conditions or negative examples to clarify when the virtual reading group should be invoked instead of a simpler literature-analysis skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal