Skill Creator

Security checks across malware telemetry and agentic risk

Overview

This skill gives visible instructions for creating and testing other skills, with no evidence of hidden, destructive, or data-stealing behavior.

Review any skill this creates or modifies before installing it, especially the description field that controls when the skill activates. Keep trigger wording specific, approve any broad activation language yourself, and inspect any referenced local scripts or subagent workflows before running them on private projects.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
95% confidence
Finding
The skill explicitly recommends making descriptions "pushy" and triggering on broad related concepts even when the user does not explicitly ask for the skill. That increases false-positive invocation and can cause this meta-skill to activate in unrelated contexts, leading it to create, modify, benchmark, or package skills when not intended, which is a risky form of overreach in an agentic environment.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal