Back to skill

Security audit

Hizal Search

Security checks across malware telemetry and agentic risk

Overview

This is a read-only Hizal context-search skill, but it is designed to activate very broadly and may query agent memory and organization-wide context without clear user control.

Install only if you want agents to consult Hizal frequently and automatically before research or codebase searches. Prefer narrowing activation to explicit prior-context requests, defaulting to project scope, and requiring approval before AGENT memory or ORG-wide searches.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
89% confidence
Finding
The self-trigger criteria are extremely broad and include many common phrases and situations, which can cause the skill to activate in routine workflows far beyond its intended scope. This creates policy and control risk: the agent may over-consult this skill, override normal tool-selection behavior, or introduce unnecessary context access patterns that expand data exposure and reduce predictability.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.