Skill Philosophy Validator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill reviewer that reads skill files and gives design feedback, with no evidence of code execution, credential use, persistence, or hidden actions.

Install this if you want a skill-design reviewer that may activate when creating or editing SKILL.md files. Be aware that its triggers are broad, so review its advice before applying changes, especially when editing the validator itself or unrelated skill metadata.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description includes very broad trigger phrases such as 'optimize skill', 'improve skill', 'update skill', and generic file-change conditions for any SKILL.md edit. This can cause unintended activation during routine editing tasks, increasing the chance that the skill runs out of context and influences unrelated skill changes.

Self-Modification

High
Category
Rogue Agent
Content
---
name: skill-philosophy-validator
description: Validates skill design against five core principles. Trigger after a SKILL.md file is created, written, edited, modified, or optimized. Also trigger when user asks to "validate skill", "check skill design", "review skill quality", "optimize skill", "improve skill", "update skill", "refine skill", "优化 skill", "改进 skill", "更新 skill", "修改 skill", "验证 skill", "检查 skill 设计", "审查 skill 质量". Do NOT trigger when the user is merely reading or viewing a SKILL.md without making changes.
metadata: {"openclaw": {"emoji": "🔍"}}
---
Confidence
88% confidence
Finding
update skill

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal