Back to skill

Security audit

info-security-expert

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only enterprise security consulting skill with broad advice scope but no hidden execution, data access, persistence, or destructive behavior.

Before installing, treat this as security consulting and document-generation guidance, not a substitute for authorized testing, legal/compliance signoff, production incident command, or architecture approval by accountable staff.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill advertises applicability to essentially all enterprise information security scenarios, which creates an overly broad activation scope for a high-trust expert persona. In agent environments, this can cause the skill to be invoked outside its truly validated boundaries, leading to overreliance on the skill for sensitive security decisions and increasing the chance of unsafe, low-context, or hallucinated guidance being treated as authoritative.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.