PrototypeSkill

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent SDLC documentation helper, with the main caveat that it automatically hands off to the next workflow step after creating the prototype document.

Install this if you want an SDLC workflow skill that writes prototype documentation from a PRD. Before using it, be aware that it is designed to continue routing automatically after prototype.md is created, so use it only in projects where that chained SDLC automation is expected.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to automatically invoke the router and continue to the next worker skill without waiting for fresh user confirmation. This reduces user control and can cause unintended chained actions, including additional file writes or workflow transitions beyond the originally expected scope, especially in multi-step SDLC automation.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal