AANA Workflow Readiness Check Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a checklist that helps an agent pause for information, permission, evidence, and safer boundaries before acting; it does not install or run code itself.

Install this if you want an agent to perform a readiness check before workflows and high-impact actions. Expect it to make the agent pause more often for clarification or approval. If you connect an external AANA checker, use only an approved integration and keep payloads redacted and minimal as the skill instructs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The instruction says to use the skill when an agent is about to begin a workflow, plan, multi-step task, tool sequence, external action, file operation, research task, customer action, code change, booking, purchase, or high-impact decision. This scope is extremely broad and lacks explicit negative examples or tighter boundaries, increasing the chance of unintended invocation across common requests.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal