Back to skill

Security audit

agent-bom compliance

Security checks across malware telemetry and agentic risk

Overview

This skill is a local compliance-reporting helper with clearly disclosed optional read-only cloud checks, but its activation phrases are broader than ideal.

Install only if you want an agent to help with compliance, SBOM, policy-as-code, or CIS benchmark work. Be aware that generic mentions of frameworks like NIST, SOC 2, or OWASP may activate it; only run CIS benchmark checks when you intend to use your local cloud credentials for read-only provider API calls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
93% confidence
Finding
Using the standalone trigger phrase "NIST" is overly broad and can cause the skill to activate for many unrelated requests that merely mention the framework. In an agent setting, broad activation increases the chance of the skill being selected out of context and then influencing tool use or compliance output in situations the user did not intend.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The phrase "policy check" is ambiguous because it could refer to many unrelated tasks, including organizational policy review, application policy logic, or security policy-as-code. This can lead to unintended invocation and misapplication of the skill's compliance or cloud-checking capabilities.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The "When to Use" section lists broad framework names such as "NIST", "SOC 2", and "OWASP" without requiring an action verb, explicit compliance intent, or scope limits. That creates a large prompt-matching surface, making accidental or adversarial triggering more likely in normal conversation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.