Capability Evolver Pro 1.0.2

Security checks across malware telemetry and agentic risk

Overview

This skill locally analyzes logs and returns recommendations, with no evidence of hidden data access or automatic changes.

Install is reasonable if you want local log diagnostics. Configure your agent to invoke it explicitly for log-analysis tasks, and redact secrets, tokens, personal data, tenant identifiers, and unnecessary stack traces before passing production or fleet logs. Review any generated recommendations before storing them or applying changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill advertises activation phrases such as "analyze these logs," "what's failing," "improve my agent," and "check system health," which are broad, everyday requests that may appear in normal conversation or adjacent tasks. This increases the chance of unintended invocation, causing logs or operational data to be processed when the user did not explicitly mean to call this skill; in a self-improvement/monitoring context, that can expose sensitive runtime information or trigger inappropriate automated diagnostics workflows.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal