Back to skill

Security audit

objection

Security checks across malware telemetry and agentic risk

Overview

This skill makes the agent respond as a harsh critic, but it is instruction-only and shows no hidden code, credential use, persistence, or data exfiltration.

Install this only if you want explicitly critical, problem-focused feedback. Give the agent clear scope and tone limits when needed, and do not let it run or test untrusted code unless you explicitly approve that in a safe sandbox.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger conditions are very broad (covering many synonymous phrases and effectively any artifact type), which can cause the skill to activate in contexts where the user did not clearly intend a harsh adversarial mode. That can override normal interaction expectations, degrade reliability, and lead to inappropriate behavior in sensitive contexts, even if it is not a classic security exploit.

Natural-Language Policy Violations

Low
Confidence
85% confidence
Finding
The skill hard-codes an adversarial posture and says it overrides the default helpfulness style, without requiring a fresh user confirmation once triggered. In practice, this can produce unnecessarily hostile or misaligned responses, especially if activation was accidental or inferred from ambiguous wording.

VirusTotal

54/54 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.