Back to skill

Security audit

Nuclei Analysis

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Nuclei scan-reporting helper with some report-quality caveats, not evidence of hidden or harmful behavior.

Install this only if you want local help turning Nuclei output into a Markdown triage report. Review the original Nuclei findings before accepting severity downgrades, filtered results, attack scenarios, or reproduction steps, especially for high-impact security decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The report generator invents attack scenarios and reproduction guidance from untrusted scan metadata rather than verified evidence, which can mislead users into acting on fabricated or exaggerated exploitability. In a security-analysis skill, this is more dangerous because operators may treat the generated Markdown as authoritative triage output and use it to prioritize remediation or testing incorrectly.

Vague Triggers

Medium
Confidence
75% confidence
Finding
The trigger phrase "review scan" is broad and could match ordinary user requests outside the intended nuclei-analysis workflow. That can cause accidental invocation of a skill that reads local scan files, runs analysis tooling, and writes reports, leading to unintended processing or side effects when the user did not mean to call this specific skill. The surrounding context makes this somewhat more concerning because the skill has operational behaviors, not just passive text generation.

VirusTotal

50/50 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.