Back to skill

Security audit

NVIDIA CUDA

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent NVIDIA CUDA optimization skill with local diagnostic scripts and no evidence of hidden data access, persistence, exfiltration, or destructive behavior.

Install this as a CUDA performance and review aid, not as a general coding policy. Run its benchmark and smoke-test scripts only on machines where GPU load and local project scanning are acceptable, and independently verify hardware purchase guidance, pricing, and availability before making buying decisions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation but does not define any trigger phrases, boundaries, or scope constraints, so the agent may activate this GPU-optimization policy in situations where it was not explicitly requested. That can cause unintended steering of model behavior, especially in mixed workloads, and increases the chance of prompt-scope confusion or policy overreach into unrelated tasks.

Static analysis

No suspicious patterns detected.