Skill Scaffold

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed skill-scaffolding CLI that creates local template files and does not show hidden data access, credential use, exfiltration, or destructive behavior.

Reasonable to install if you want a local skill-template generator. Treat generated SKILL.md content as editable source: review descriptions, triggers, and author-supplied text before publishing or letting another agent rely on it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad enough to activate on generic requests like 'create a skill' or 'new skill template', which may cause an agent to invoke this skill outside the user's intended context. In an agent ecosystem, overbroad routing can lead to unintended tool use, confusion, or execution of scaffolding workflows when the user only asked for advice or a different platform-specific action.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal