Back to skill

Security audit

Diagnose

Security checks across malware telemetry and agentic risk

Overview

This is a debugging workflow guide with no executable payload, though its broad debug triggers may load it more often than some users expect.

Install this if you want agents to follow a structured debugging methodology. Because the triggers include common words like debug and diagnose, expect it to activate for many troubleshooting tasks; review any proposed commands, traces, or production instrumentation before allowing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list is broad and includes generic multilingual terms such as 'debug', 'diagnose', and issue-fixing phrases, which can cause the skill to auto-activate in situations beyond the author's intended scope. Because this skill influences agent behavior and debugging workflow, unintended invocation could override a more appropriate skill, cause unnecessary tool use, or steer the agent into operational paths the user did not explicitly request.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The auto-loading rule states that the skill is loaded when a task is classified as '排错/debug', but it does not define the classifier, thresholds, or tie-breaking behavior with other skills. This ambiguity can lead to accidental activation, inconsistent routing, and unsafe delegation decisions if the agent interprets loosely related tasks as debugging tasks.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list contains very broad, common terms such as 'debug', '排错', and '诊断', which are likely to appear in many ordinary coding conversations. This can cause the skill to activate unintentionally and influence workflows outside the user's explicit intent, increasing the risk of prompt/skill routing errors or unexpected behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.