Back to skill

Security audit

Legible Agent Output

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for making agent messages easier to read, with the main caveat that it may oversimplify technical details if applied too broadly.

Install this if you want agents to make status messages, errors, and plans easier for non-technical users to understand. Avoid applying it to logs, debugging output, compliance records, or technical workflows where exact error codes, file paths, IDs, or command names must remain visible; use the skill's parenthetical or secondary-detail pattern for traceability.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger conditions are very broad and cover common categories such as task titles, status messages, error messages, and plan summaries. In practice this can cause the skill to activate across a large portion of agent-user interactions, overriding more context-appropriate behaviors and increasing the chance that important technical detail is suppressed or rewritten when precision matters.

Natural-Language Policy Violations

Low
Confidence
71% confidence
Finding
The skill assumes a single audience profile, 'a non-technical human,' without checking user preference, locale, or need for technical fidelity. That can lead to over-simplification, loss of necessary detail, or mismatched wording for users who need exact terminology for support, compliance, or debugging.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.