Back to skill

Security audit

Kano Model Strategist

Security checks across malware telemetry and agentic risk

Overview

This appears to be a product-planning guidance skill with no evidence of malware, exfiltration, persistence, or privileged system access.

Install this if you want a strongly opinionated feature-pruning or Kano-analysis assistant. Be aware it may push back during general backlog or MVP discussions; ask it explicitly when you want that framework, and ignore it when you only want neutral product-planning help.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list is broad enough to match ordinary product-planning conversations such as backlog triage, MVP scoping, or asking whether something is a must-have. That can cause the skill to activate outside narrowly intended Kano-analysis contexts, steering conversations with an overly opinionated 'start with NO' stance and potentially producing misaligned recommendations.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The front-matter load condition is broad and subjective ('when auditing an existing product, pushing back on a feature, or running the prune'), which can cause the skill component to activate in more contexts than necessary. In agent systems, ambiguous activation increases prompt-surface exposure and the chance that this content influences unrelated tasks, creating unintended behavior or policy bypass opportunities through over-inclusion rather than through the checklist text itself.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.