Phy Research Deep

Security checks across malware telemetry and agentic risk

Overview

This skill is an instruction-only web research workflow that may run multiple searches, but it does not install code, seek secrets, persist, or modify user data.

Install this if you want your agent to perform structured multi-source web research. Be aware that research-like wording may trigger several web searches and a few page fetches, so avoid including sensitive private details in prompts that could become search queries and review important citations before relying on the results.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description and usage guidance are broad enough to match very common user intents such as 'research' or 'find out about,' which can cause the skill to activate in many ordinary conversations. Over-broad activation increases the chance of unintended tool use, unnecessary web access, and delegation to a workflow the user did not explicitly request.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger list contains ambiguous everyday-language activators like 'research,' 'investigate,' and 'find out about,' which are likely to appear in benign user requests that do not warrant this powerful workflow. In an agent system, this can lead to over-triggering, causing excessive searches, unnecessary external data access, higher cost, and potentially privacy-impacting web queries based on loosely phrased user input.

VirusTotal

No VirusTotal findings

View on VirusTotal