Back to skill

Security audit

Local LLM Setup Advisor

Security checks across malware telemetry and agentic risk

Overview

This is a local LLM setup advice skill with no executable code or hidden data access, though its activation wording is broader than ideal.

Before installing, understand that this skill may activate for some broad local AI, privacy, or software workflow requests. Its behavior is limited to guidance for local LLM setup, so the main practical concern is irrelevant routing rather than system compromise.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentences are broad enough that the skill could activate for loosely related requests, causing unintended routing and potentially injecting local-LLM-specific guidance where it was not requested. In an agentic environment, ambiguous activation increases the chance of workflow misexecution, policy bypass through accidental tool selection, or user confusion about what capability is being invoked.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad and partly template-like, including generic wording such as 'I need a practical workflow for...' and 'Help me ...', which can overlap with ordinary user requests outside a narrowly scoped invocation. In an agent-routing system, this can cause the skill to activate unintentionally, leading to misrouting, unexpected prompt injection surface expansion, or the skill handling requests it was not meant to process.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is broad enough to activate on generic requests about software, data, workflows, or implementation support, which can cause inappropriate routing to this skill outside its intended local-LLM niche. Overbroad activation increases the chance that unrelated user tasks are handled under the wrong assumptions, potentially producing misleading guidance or bypassing more appropriate specialized skills.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Example triggers using everyday phrases like 'Help me' and 'I need a practical workflow' are dangerously generic because they can match a wide range of ordinary user requests with no meaningful connection to local LLM setup. This can cause accidental skill invocation and scope confusion, making the agent more likely to respond with irrelevant or incorrect guidance.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords include broad terms such as "privacy" alongside common technical phrases, which can cause the skill to activate for ordinary conversations that are only loosely related to local LLM setup. Over-broad activation increases the chance of unintended routing, causing users to receive irrelevant or overly specialized guidance and potentially displacing a more appropriate skill.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger phrases are highly generic (for example, "Help me" and "I need a practical workflow") and embed a long demand statement that is not a realistic or specific user intent. Ambiguous examples can teach the routing system to match on ordinary language rather than on the domain-specific need, leading to false activations and degraded safety and usability.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt uses a very broad natural-language invocation phrase ('Use $local-llm-setup-advisor to help me...') that can overlap with ordinary user requests about local LLMs, CPUs, GPUs, or practical setup help. Because implicit invocation is enabled, this increases the chance the skill is auto-triggered in contexts the user did not explicitly intend, expanding the attack surface for prompt injection, misrouting, or unintended tool behavior.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger section includes a generic invocation pattern ('Help me ...', 'I need a practical workflow for ...', 'Use $local-llm-setup-advisor ...') tied to a very broad requirement statement rather than a narrowly scoped user intent. Overly broad trigger phrasing can cause the skill to activate in unintended contexts, leading to prompt/skill hijacking, irrelevant execution, or routing sensitive requests into a local-LLM workflow that was not actually requested.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.