Back to skill

Security audit

Create Content

Security checks across malware telemetry and agentic risk

Overview

This is a simple writing-assistant skill that fits its purpose, but users should limit what personal notes it may search for ideas.

Reasonable to install as a content-writing helper. Before using the idea-discovery flow, tell the agent exactly which notes, folders, journals, or date range it may review, and keep confidential or highly personal material out of scope. Review all drafts before posting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The usage trigger accepts very broad natural-language input such as any rough idea or 'help me figure out what to post,' which can overlap with ordinary conversation and cause the skill to activate unexpectedly. In an agent environment, this increases the chance of unsolicited behavior and unintended access to user context when the user did not clearly intend to invoke this skill.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The quick commands like 'explore,' 'help me think,' or platform-post requests are generic phrases commonly used in everyday chats, making accidental triggering likely. Because these shortcuts can bypass normal clarification flow, they may cause the skill to take over interactions or generate content when the user intended a general assistant response instead.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The instruction to search recent notes, journal entries, and sessions directs the agent toward potentially sensitive personal data without any warning, consent step, or minimization guidance. In this context, the skill is a content ideation tool, so searching private material may expose intimate or confidential information unnecessarily and could surface it into generated drafts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.