Community Onboarding

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk community onboarding helper with broad triggers but no code execution, credential access, persistence, or hidden behavior.

Install this if you want the assistant to help onboard new community members and explain $NEURONS conservatively. Consider narrowing or manually routing the generic triggers if your agent has many support workflows, and verify the publisher/source if the registry version mismatch matters to your deployment process.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list contains generic phrases like "new member," "getting started," and "how do I start," which can match ordinary user messages outside the intended onboarding context. This can cause the skill to activate unexpectedly, leading to response hijacking or user confusion if it overrides a more appropriate skill.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal