Back to skill

Security audit

situated planning mode

Security checks across malware telemetry and agentic risk

Overview

This is a planning-only skill with disclosed memory and research-subagent use, and I found no hidden code, install hooks, credential access, or destructive behavior.

Install if you want a structured planning workflow. Be aware that it may search prior memory and spawn research subagents during planning; restrict those platform permissions if you want every research step approved manually or if subagents can access private or paid resources in your environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation description is broad enough to match many normal user requests involving projects, tasks, or planning, which can cause this skill to trigger outside its intended niche. Because the skill then steers the interaction into a fixed planning workflow and may autonomously launch subagent research, accidental activation can alter agent behavior, expand scope, and create unnecessary tool use or data exposure risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.