Back to skill

Security audit

沟通五部曲

Security checks across malware telemetry and agentic risk

Overview

This is a text-only communication workflow skill, with a clear privacy caveat because it encourages saving decisions and reflections to memory.

Install this if you want the agent to use a structured five-step reflection process. Before using it with private work, confirm whether memory, Obsidian, ChromaDB, or web tools are enabled, and require redaction or confirmation before saving secrets, credentials, confidential command output, regulated data, or sensitive business details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs that decision rationale, execution results, and reflections should be automatically stored into persistent memory/knowledge repositories. This creates a real risk of retaining sensitive user content, secrets, internal operational details, or regulated data without consent, minimization, or clear scoping, and can enable later unintended disclosure through retrieval.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal