Skill Creator

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed helper for creating, testing, improving, and packaging skills, with no evidence of hidden exfiltration, destructive behavior, or privilege escalation.

Install this only if you want an agent to help create or revise skills. Use a dedicated workspace, review any generated or modified SKILL.md before enabling it, avoid putting secrets into eval prompts or packaged folders, and verify any external local evaluation scripts before allowing the agent to run them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill explicitly recommends making descriptions 'pushy' and triggering on broad common-language contexts, which increases the chance of over-triggering on unrelated user requests. In context, this is more dangerous because the skill has powerful file and shell-oriented workflows, so accidental invocation can lead to unnecessary workspace creation, script execution, or process launching.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal