Back to skill

Security audit

prompt-engineering

Security checks across malware telemetry and agentic risk

Overview

This skill is a prompt-engineering guide with disclosed reasoning and tool-use patterns, and it does not contain executable code, persistence, credential handling, or hidden behavior.

Before installing, understand that this skill may steer an agent toward explicit reasoning templates and ReAct-style tool use when a task needs search, browsing, file reads, or calculation. That behavior is disclosed and purpose-aligned, but users should still rely on the host agent's normal approval and permission controls for sensitive commands or external actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
The skill documents ReAct patterns that explicitly map reasoning steps to tool calls such as web_search/read/exec/browser, expanding a prompt-engineering skill into actionable tool-invocation guidance. That can encourage downstream agents to perform external actions or code execution without clearly scoping permissions, approvals, or safety gates, increasing the risk of overbroad tool use and prompt-to-action escalation.

Vague Triggers

Medium
Confidence
83% confidence
Finding
Several triggers are broad conceptual phrases like 'prompt engineering', '推理模式', and multi-agent orchestration terms that can match ordinary discussion rather than intentional invocation. This can cause accidental activation of the skill in unrelated conversations, unexpectedly imposing its instructions and routing behavior onto benign requests.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes very broad everyday terms such as "搜索", "查询", "计划", and "步骤", which can cause the skill to activate in contexts where the user did not intend prompt-engineering behavior. In an agent system, accidental activation can alter routing, inject hidden reasoning templates, or cause unexpected tool-oriented behavior, increasing the attack surface and creating prompt-confusion risks.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.