Back to skill

Security audit

Nsfc

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a writing-workflow helper, with broad legacy command aliases noted as a routing concern but no evidence of hidden, privileged, or harmful behavior.

Installers should be aware that generic words like write, review, outline, template, optimize, and checklist may activate the skill unexpectedly. Prefer explicit namespaced commands when possible, but the available evidence does not show malicious behavior or sensitive access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The report documents multiple legacy trigger phrases such as `write`, `review`, `outline`, `template`, `optimize`, and `checklist` remaining valid as standalone commands. These are generic everyday words that can be accidentally invoked from normal conversation, causing unintended skill activation, prompt-routing mistakes, or cross-skill interference. In an agent environment, broad triggers increase the attack surface because adversarial or incidental text can more easily activate privileged workflow behavior.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal