Doc Generator

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent AnyGen document-generation integration, but it tells the agent to install an additional unpinned workflow skill automatically if it is missing.

Review this skill before installing. Use it only if you are comfortable sending document prompts and source material to AnyGen. Do not allow the additional workflow skill installation unless you have reviewed and approved that dependency, preferably with a known source and version.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger text is extremely broad and instructs the agent to use this skill for nearly any request involving writing or structured output. That can cause unintended invocation in situations where a more specific, safer, or more appropriate skill should be selected, increasing the chance of unnecessary external data transfer to AnyGen or bypassing user intent about tooling.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal