Back to skill

Security audit

Knowledge Router

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent knowledge-search router, but it can automatically search prior conversation memory from very broad prompts without a clear consent step.

Review this skill before installing if your memory stores may contain sensitive personal, business, or project information. It should ideally require explicit memory-recall wording or confirmation before querying prior conversations, and memory-derived answers should be clearly labeled.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad enough to match common user utterances such as '帮我找' or 'XX是什么', which can cause the skill to activate unexpectedly. In this skill, accidental activation is more dangerous because it can route requests into memory and knowledge sources containing prior conversation data or internal structured knowledge, increasing the chance of unintended data exposure or over-collection.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly queries prior conversation memory and structured memory stores but does not require a user-facing notice or confirmation before accessing them. This is risky because users may ask a broad knowledge question and unknowingly trigger retrieval of prior conversation artifacts, exposing personal, sensitive, or contextually private information beyond their expectation.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.