Back to skill

Security audit

brainstorming

Security checks across malware telemetry and agentic risk

Overview

This is a transparent brainstorming workflow skill, but users should keep control over when it reads a project and when it writes or commits design documents.

Install this if you want a structured design-first workflow. Before using it, be aware that it may read repository context and may ask the agent to create and commit design documents; keep file writes and git commits subject to your explicit approval.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill declares that it "MUST" be used before any creative work, which is an unusually broad trigger that can cause the agent to invoke this workflow in many unrelated situations. That creates a control-flow and safety issue because it may unnecessarily inspect project state and steer behavior even when the user did not request planning, increasing the chance of unintended actions or prompt-scope expansion.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to write a design document to the repository and commit it to git as part of the workflow, but it does not require confirmation or warn that this modifies user data. In practice, this can lead to unauthorized file creation and version-control changes during what should be a brainstorming phase, especially if the skill is auto-invoked from its broad trigger.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal