Back to skill

Security audit

Local LLM Setup Advisor

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only local LLM setup advisor; its activation wording is broad, but it does not request hidden access, persistence, credentials, or destructive authority.

Installers should understand that this skill may be invoked for broad local-AI or privacy-related requests because of its loose trigger wording. It is otherwise a low-risk advisory skill with no executable code or privileged behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad and repetitive, centering on a long generic demand statement rather than narrow, user-confirmed activation criteria. This can cause the skill to activate in situations where the user did not clearly request it, leading to prompt hijacking of normal conversations, misrouting, or over-application of the skill’s guidance.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description and trigger scope are broad enough to match many ordinary requests about software, data, privacy, or local AI, which can cause unintended activation. Over-broad activation is dangerous because it can route unrelated user tasks into this skill, leading to incorrect guidance, policy bypass through misclassification, or interference with more appropriate skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger phrase is extremely generic ('Help me', 'I need a practical workflow') with only a truncated requirement pasted after it, making accidental or ambiguous activation more likely. This increases the chance that the skill is selected for loosely related requests, reducing routing accuracy and potentially causing users to receive irrelevant or unsafe advice outside the intended scope.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger description is broad and loosely scoped, so the skill may activate for many general requests about software, local AI, or privacy that were not intended for this specific workflow. Overbroad activation can cause inappropriate routing, reduce user control, and increase the chance that this skill’s assumptions or instructions override a better-matched skill.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example trigger phrases overlap with ordinary conversational requests like 'Help me' and 'I need a practical workflow,' which makes accidental invocation more likely. This can lead to unintended skill selection and response shaping in situations where the user did not actually request this specialized advisor.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill content is primarily in Chinese and effectively enforces a locale without offering user choice, which can cause misunderstanding of instructions, constraints, or outputs for users expecting another language. In security-sensitive or operational contexts, forced locale behavior increases the risk of misconfiguration or missed warnings due to comprehension gaps.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt is overly broad and directly encourages use of the skill for a wide class of requests, while the policy also allows implicit invocation. This combination can cause the skill to activate in situations the user did not clearly intend, which may lead to unnecessary routing, confusing behavior, or exposure of the skill in contexts where it is not the best match.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentence is extremely broad and partially templated, making accidental invocation plausible for ordinary user requests. Over-broad activation can cause the wrong skill to take control, producing irrelevant or misleading local-LLM guidance when the user did not explicitly request this workflow.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The invocation guidance lacks precise boundaries and includes generic request patterns that overlap with normal conversation. In an agentic environment, this increases the risk of inappropriate skill selection, prompt-routing errors, and unintended disclosure or generation of advice outside the user’s actual need.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.