Back to skill

Security audit

arch-sign-off

Security checks across malware telemetry and agentic risk

Overview

This skill makes a small, disclosed article-ending edit in a narrow docs folder, with no evidence of hidden code, credential access, network use, or persistence.

Install this only if you want every ai-thoughts/docs/ article to receive this exact sign-off by default. Users who need per-article editorial approval, localized endings, or publication-policy compliance should opt out explicitly or revise the skill before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill is designed to activate by default for essentially every article-writing or finishing task in ai-thoughts/docs/, unless the user explicitly opts out. That broad trigger can cause unintended file modifications and surprising behavior, especially when the user did not request this specific content change.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill instructs the agent to automatically edit files by appending content, but it does not require clear disclosure or confirmation to the user before making the change. Silent automatic edits increase the risk of integrity issues, user surprise, and unauthorized content modification in normal writing workflows.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill mandates a specific English sign-off in both English and Chinese articles without user opt-in, overriding language expectations and editorial control. While lower severity than arbitrary code or data exfiltration issues, it can still cause unwanted content injection, policy noncompliance, or reputational problems in multilingual publishing contexts.

VirusTotal

43/43 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.