Back to skill

Security audit

navigation-menu-generator

Security checks across malware telemetry and agentic risk

Overview

This appears to be a navigation-design guidance skill, with the main issue being overly broad activation wording rather than harmful behavior.

Before installing, be aware that this skill may activate when you mention general navigation or site-structure topics. Use it for explicit navigation-menu work, and consider narrowing its trigger phrases if accidental activation becomes noisy.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation trigger list includes very generic phrases such as "navigation" and "site structure," which can match ordinary conversation and cause the skill to activate in contexts the user did not intend. While the skill content itself is not harmful, over-broad auto-invocation can lead to incorrect routing, context pollution, and reduced reliability of agent behavior.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.