Weighted Column

Security checks across malware telemetry and agentic risk

Overview

This is a simple instruction-only business charting skill with a minor risk of being triggered too broadly, but no system access or hidden behavior.

Reasonable to install if you want a template for profitability and market-share chart analysis. Review whether a weighted-column chart is actually the right format when the skill activates on broad business terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list contains broad, ambiguous terms such as "bubble chart," "profitability," and "market share," which are common across many business-analysis requests and could cause the skill to activate when a user did not specifically ask for this chart type. Unintended invocation can lead to irrelevant workflow hijacking, confusing outputs, and increased risk that the agent applies the wrong analytical framework to user data or decisions.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal