lin-skill-demo

Security checks across malware telemetry and agentic risk

Overview

This is a small paid-skill demo that locally checks a license key before printing demo output, with no evidence of hidden data access, persistence, or exfiltration.

Reasonable to install as a paid-skill template demo. Use only a license key intended for this skill, and treat it as a basic example rather than production-grade licensing infrastructure.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger list contains broad phrases such as "收费技能", "付费功能", and "授权验证", which are generic concepts rather than uniquely identifying this skill. In an agent ecosystem, overly broad triggers can cause unintended invocation, routing conflicts, or make the skill activate in contexts where users did not explicitly request it, increasing the chance of misuse or confusing behavior.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal