Back to skill

Security audit

Network-AI

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local multi-agent coordination helper, with persistence and advisory permission tokens that are expected for its purpose.

Install this only for trusted local workspaces where multi-agent coordination is actually needed. Do not put secrets, credentials, or PII in justifications, blackboard entries, or project context; protect or periodically clear the data directory. Treat grant tokens as advisory hints, not real authorization, and configure any host-level delegation or external API access with explicit limits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill exposes high-level orchestration capabilities such as task delegation, parallel agent spawning, blackboard updates, and persistent context injection without defining strict trigger conditions, caller restrictions, or narrow operational boundaries in the manifest. In a multi-agent orchestration skill, this ambiguity can enable over-broad invocation, prompt/context abuse, excessive agent fan-out, or misuse of permission-related flows by higher-level tooling that trusts the manifest descriptions.

VirusTotal

53/53 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.