Back to skill

Security audit

software-spec-writing

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation workflow guide that writes and maintains project specification files, with no hidden execution, credential use, or unrelated data access found.

Install this if you want the agent to enforce a strict specification-writing workflow. Expect it to maintain spec-coverage.yaml, ask for missing requirements, and prefer Mermaid diagrams; avoid using it where your project needs a looser documentation style or non-Mermaid diagram standards.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The phrase covering 'technical decisions' and discovering 'external constraints' lacks clear boundaries, so the skill may activate during ordinary conversation, architecture brainstorming, or implementation work. In practice this can cause the skill to seize control of workflows beyond document authoring, forcing procedural requirements that may block or distort unrelated tasks.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The phrase covering 'technical decisions' and discovering 'external constraints' lacks clear boundaries, so the skill may activate during ordinary conversation, architecture brainstorming, or implementation work. In practice this can cause the skill to seize control of workflows beyond document authoring, forcing procedural requirements that may block or distort unrelated tasks.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The instruction 'Mermaid' as the only allowed diagram format imposes a specific output language/format without user opt-in. While not directly a code-execution issue, format coercion can conflict with user preferences, toolchain constraints, accessibility needs, or repository standards, causing inappropriate outputs or workflow disruption.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.