Back to skill

Security audit

Prototype

Security checks across malware telemetry and agentic risk

Overview

This skill gives disclosed guidance for building temporary prototypes and does not include hidden execution, credential access, exfiltration, or destructive behavior.

Install this if you want agent help creating quick throwaway prototypes. Be aware that generic words like prototype or demo may invoke it, and review any generated prototype files before keeping, committing, or connecting them to real data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes generic terms such as "prototype", "demo", and broad design-related phrases that are likely to match many normal coding or planning requests. That can cause this skill to activate outside its intended scope and steer the agent into prototype behavior where a narrower or safer skill should have been selected.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The statement that the skill auto-loads for tasks classified as "原型/demo/验证想法" defines invocation boundaries too loosely. In an agentic system, ambiguous autoloading can misroute many ordinary tasks into this skill, causing inappropriate behavior selection and increasing the chance that low-safety prototype practices are applied in the wrong context.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes very broad terms such as "prototype", "demo", and idea-validation phrases that are common in ordinary coding or design conversations. This can cause unintended activation of the skill in contexts the user did not explicitly request, increasing the chance that the agent applies prototype-oriented behavior or dependencies when inappropriate.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.