Back to skill

Security audit

Implementation Plan

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable planning skill whose broad trigger wording may be noisy but does not create a material security concern.

Install this if you want structured implementation plans. Be aware it may activate on broad build or problem-solving requests, so explicitly ask for direct coding, debugging, or another workflow when you do not want a plan.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill activates on very broad, generic prompts such as asking to build an app or solve a problem, which can cause it to trigger in situations where a planning skill was not explicitly intended. This can lead to incorrect routing, overshadow more appropriate skills, and increase the chance that sensitive or high-risk requests are transformed into implementation guidance without sufficient domain-specific safeguards.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.