backend-api-designer

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only backend design skill with disclosed, purpose-aligned project reading guidance and no executable code or credential use.

Install only if you want an agent to help with backend architecture and API/database design. When using the engineering-analysis mode, point it at a scoped project directory and avoid including secrets or unrelated private files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list contains very broad phrases such as '需求分析', '工程分析', and '流程图', which are common in ordinary development conversations and can cause the skill to activate outside its intended scope. Over-broad activation can hijack unrelated user requests, leading the agent to apply this skill inappropriately, override better-matched tools, or expose repository structure through unnecessary project analysis steps.

VirusTotal

46/46 vendors flagged this skill as clean.

View on VirusTotal