Back to skill

Security audit

tech-to-skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a transparent document-processing workflow that turns user-provided technical material into local skill files with source references.

Before installing, understand that generated reference files may copy excerpts from the source material you provide. Use an output directory you control and review generated skills before sharing or installing them elsewhere, especially when distilling private repositories or internal documents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The frontmatter description is explicitly defined as the only basis for agent activation, but the template leaves trigger wording largely open-ended. In a system that auto-activates skills from manifest text, ambiguous or overly broad activation criteria can cause unintended invocation, leading the agent to apply the wrong procedure or operate outside intended scope.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The 'When to use' section asks for situations and language signals but does not require precise trigger boundaries, thresholds, or disambiguators. That makes it easy for generated skills to match loosely related requests, increasing the chance of misrouting, overreach, or unsafe automation when similar domains overlap.

Vague Triggers

Low
Confidence
80% confidence
Finding
Although a 'When NOT to use' section exists, the template does not enforce meaningful exclusion conditions or sufficient detail. If exclusions are omitted or superficial, the skill may still activate in inappropriate contexts, reducing reliability and creating a path for accidental misuse.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.