Asset Extension

Security checks across malware telemetry and agentic risk

Overview

This is a simple business-analysis skill with no code, credentials, persistence, or external access requested.

Safe to install as an instruction-only business strategy template. Be aware it may activate on broad business phrasing, and review any strategic or investment recommendations before acting on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are generic business terms such as 'leverage assets' and 'resource utilization', which can easily appear in ordinary conversation and cause unintended skill invocation. This is primarily a safety and routing issue rather than direct code execution, but it can lead to the wrong skill handling user input, increasing the chance of misleading analysis or bypassing more appropriate safeguards in other skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal