Back to skill

Security audit

Skill Distiller

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow skill for turning repeated problems into reusable processes, with broad routing language but no hidden execution, credential access, persistence, or destructive behavior.

Install this if you want a general assistant for formalizing repeatable workflows or drafting skills. Be aware it may trigger too broadly in generic planning conversations; consider narrowing its trigger language or disabling it if it interferes with more specific skills. The crypto and purchase metadata tags do not match the reviewed artifacts and should not be treated as necessary permissions for this skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is broad enough to activate on many normal user requests about solving recurring problems or organizing work. Over-broad activation can cause unintended routing to this skill, leading the agent to apply an irrelevant methodology, override more appropriate skills, or unnecessarily expose internal process/tooling behavior.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are abstract concepts rather than distinctive invocation phrases, which increases the chance of accidental or overly aggressive activation. In an agent system, vague triggers can degrade reliability and safety by causing this skill to intercept unrelated conversations and steer outputs into generalized process-building even when the user did not request it.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.