Back to skill

Security audit

Web Research Subagent

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent web-research workflow with clear source-evaluation guidance and no hidden install, credential, persistence, or destructive behavior.

Install this only if you want the agent to perform web research and possibly delegate bounded research tasks. Avoid including secrets, private files, account data, or sensitive local context in research prompts unless truly necessary, and keep confirmations in place before acting on web-derived instructions or making consequential changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
72% confidence
Finding
The activation criteria are very broad ('use when a task requires current web knowledge, domain research, source evaluation...'), which could cause the skill to be invoked for many routine tasks and unnecessarily expand exposure to untrusted web content. In agentic systems, over-broad routing increases the chance that sensitive, implementation-adjacent, or low-need tasks are delegated to browsing/research flows, raising prompt-injection and context-sprawl risk even though the skill includes some good safety guidance.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.