Ollama

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a local Ollama and RAG setup helper, with only a minor concern that its activation wording is broad.

Install is reasonable if you want help setting up or troubleshooting Ollama/local RAG workflows. Be aware it may activate on broad local-AI terms, so use it intentionally and review any setup commands before running them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill directs activation on very broad, common topic mentions such as 'Ollama', 'local LLMs', 'embeddings', or 'local RAG', without sufficiently narrow gating conditions. This can cause unintended invocation in loosely related conversations, increasing the chance the skill collects environment details or influences workflow when the user did not explicitly request it.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal