Skill Optimizer

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed skill-quality checker with broad activation wording but no evidence of hidden, destructive, or data-stealing behavior.

Install this if you want help checking or improving skill files. Use it on clearly specified skill paths, review any proposed edits before allowing writes or command execution, and consider narrowing its activation text if you maintain the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger description is very broad, including generic phrases like checking, optimizing, evaluating, or batch-processing skills, which can cause the skill to activate in contexts the user did not intend. Because this skill has powerful tools (`Bash`, `Write`, `Exec`), unintended invocation increases the chance of unnecessary file access, script execution, or changes being proposed or performed in the wrong workspace.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal