agent-bom compliance

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed compliance-reporting helper with local analysis by default and optional, user-initiated read-only cloud checks.

Install only if you want an agent to help with compliance reports, SBOMs, policy checks, or CIS benchmarks. For CIS cloud checks, use least-privilege read-only cloud credentials and only run them when you intend to query AWS, Azure, GCP, or Snowflake account metadata.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes very broad standalone terms like "NIST", "OWASP", and "EU AI Act", which can cause the skill to be selected for generic framework-related queries outside its intended compliance-evaluation scope. This creates a prompt-routing risk where the skill may activate in contexts involving advisory, interpretation, or unrelated security tasks, increasing the chance of inappropriate tool use or confusing capability escalation.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The "When to Use" section repeats broad framework names as standalone invocation cues without constraints, which increases the likelihood of over-triggering on common security terminology. In an agent environment, this can misroute user requests into a skill that may read local files or initiate cloud benchmark workflows when the user only wanted general guidance.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal