Deep Research

Security checks across malware telemetry and agentic risk

Overview

This skill is a transparent deep-research writing workflow that uses web sources and local markdown drafts without hidden execution or credential access.

Install this if you want an agent to perform exhaustive cited research. Set clear limits on topic scope, source types, browsing depth, languages, output length, and whether it may create intermediate markdown draft files in your workspace.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger description is broad enough to activate on many ordinary requests for analysis, reports, or thorough explanations, which can cause the agent to invoke an expensive and highly capable research workflow when it is unnecessary. Over-broad triggering increases the attack surface for prompt steering, unnecessary web access, excessive tool use, and policy drift because the skill may engage in multi-step external research for benign requests that do not require it.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal