Back to skill

Security audit

Hizal Register Focus

Security checks across malware telemetry and agentic risk

Overview

This markdown-only skill records the agent's current task so related context can be added, with a disclosed risk that it may activate too broadly.

Install this if you want automatic task-focus registration for context injection. Use specific tags and be aware that broad trigger wording may cause the agent to update focus during normal planning language, which could pull in irrelevant context.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill advertises self-triggering on very broad, open-ended phrases such as any time the agent articulates a specific goal or says what it is working on. This can cause over-activation and unintended context injection, which may expose irrelevant or sensitive session context, steer agent behavior unexpectedly, or create prompt-surface expansion without explicit user intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.