Back to skill

Security audit

Product

Security checks across malware telemetry and agentic risk

Overview

This is a product-recommendation workflow skill with broad triggers, but it does not request execution authority, credentials, persistence, or destructive capabilities.

Install this if you want a broad structured framework for product comparisons. Be aware it may activate for many recommendation-style prompts, so use a more specialized skill or ask for expert advice for regulated domains such as medical, financial, legal, or purchasing execution tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill declares very broad trigger phrases such as general recommendation, comparison, and purchase-selection requests across "all industries / all categories," which can match many ordinary user prompts unintentionally. This creates overbroad activation risk: the agent may enter this skill when the user did not intend a structured procurement-style workflow, causing context hijacking, inappropriate recommendations in regulated domains, or bypass of more specialized safeguards.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger table uses catch-all labels like "推荐 / 测评 / 对比 / 该买哪个 / 适合我的 X / 选型清单," while the negative case only handles users asking what the skill does. Because the boundaries are underspecified, many routine conversational requests could activate the skill without sufficient intent checking, increasing the chance of misrouting and unsafe handling of edge cases that need domain-specific controls.

VirusTotal

52/52 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.