Back to skill

Security audit

Local LLM Setup Advisor

Security checks across malware telemetry and agentic risk

Overview

This skill is a local LLM setup advice package with no executable code, persistence, credential handling, or hidden data access.

Before installing, note that this skill may activate on some broad local-AI or privacy-related requests. Its content is low risk and advice-oriented, but users who manage many skills may want narrower triggers to avoid misrouting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentences are broad enough that the skill may activate for loosely related requests, causing unintended invocation and increasing the chance that users receive guidance outside the precise local-LLM setup scope. In an agent ecosystem, ambiguous activation can lead to misrouting, privacy issues, or low-quality automation decisions because the skill lacks clear boundaries and exclusions.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad, repetitive, and partially templated, which can cause the skill to activate for loosely related requests rather than clear user intent. In an agent environment, ambiguous activation increases the chance of misrouting prompts or invoking this skill when a more appropriate or safer workflow should handle the request.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description is broad and mixes concrete topics with generic request types like 'practical workflow, artifact, checklist, analysis, or implementation support.' That can cause the skill to activate for loosely related prompts and override a more appropriate specialized skill, increasing the chance of unintended handling of user requests.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords include ambiguous terms, especially 'privacy,' which is common across many unrelated domains. This creates collision risk where the skill may be invoked for general privacy questions rather than local LLM setup, leading to misrouting and potentially lower-quality or unsafe guidance if users receive advice outside the skill's intended scope.

Vague Triggers

Low
Confidence
89% confidence
Finding
The trigger section provides positive examples but no negative boundaries, so the routing logic lacks guidance on when not to activate. Without exclusions, similar but out-of-scope requests may be captured, which increases false activations and weakens skill-selection reliability.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation description is broad and mixes many generic software/AI-related terms, which can cause the skill to trigger in situations where the user did not intend to invoke it. This is not a code-execution issue, but it can lead to context hijacking, irrelevant guidance, or accidental override of a more appropriate skill during normal conversations.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The example trigger phrases closely resemble ordinary user requests and contain highly reusable language like 'Help me' and 'I need a practical workflow,' making accidental activation more likely. In a multi-skill environment, this can misroute user intent and cause the assistant to apply this skill when a general response or different skill would be safer and more accurate.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt is broad and generic, encouraging the skill to be invoked for a wide range of loosely related requests without tight scoping. In combination with agent routing, this can cause unintended activation, expose users to irrelevant or lower-quality guidance, and increase the attack surface for prompt-injection or misrouting through an overpermissive trigger.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Enabling implicit invocation without precise activation criteria allows the system to call this skill automatically for ambiguous requests. That increases the chance of unintended tool use, context leakage across skills, and susceptibility to adversarial phrasing that steers routing into this skill when it is not actually appropriate.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentence is so generic and malformed that it can match routine user phrasing unrelated to a narrowly scoped skill, causing the agent to invoke this skill in unintended contexts. Over-broad activation increases the chance of prompt-space capture, misrouting, and inappropriate influence over conversations that only loosely mention local AI or hardware constraints.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.