ai-agent-helper

Security checks across malware telemetry and agentic risk

Overview

This is a small prompt-help skill with a visible optional SkillBoss API example and no hidden install scripts or persistence.

Safe to install as a prompt and agent-design helper. If you use the SkillBoss API example, provide an API key only intentionally and avoid sending secrets, private prompts, personal data, or sensitive business content unless you trust SkillBoss and its routing and retention practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are very broad and generic, which can cause the skill to activate in contexts the user did not intend. Unintended invocation is dangerous because it may expose users to hidden behaviors in the skill, including external API usage and prompt-shaping, without clear consent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documented code sends user-provided messages to an external endpoint using an API key, but the skill does not clearly warn users that their inputs may leave the local environment. This creates a real privacy and compliance risk because sensitive prompts, internal data, or regulated content could be transmitted to a third party without informed consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal