Document Summary

Security checks across malware telemetry and agentic risk

Overview

This is a simple document-summary skill with no executable code, network behavior, credential use, or hidden persistence.

Install if you want a lightweight helper for summarizing provided technical text. Be aware that broad trigger words may activate it for ordinary summary requests, so avoid sending confidential content unless you intend this skill to process it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation phrases are broad, generic, and overlap with common user requests such as 'summarize' or 'summary', which can cause the skill to activate unintentionally in contexts beyond its intended scope. This increases the chance of prompt-routing confusion, accidental data exposure to the skill, or misuse on arbitrary content without clear user intent.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The invocation phrases are broad enough to match many ordinary user requests such as 'summarize' or 'summary', which can cause the skill to activate unexpectedly outside a clearly scoped document-processing context. In an agent environment, overbroad activation can lead to prompt hijacking of normal conversations, unintended handling of sensitive content, or interference with more appropriate skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal