Back to skill

Security audit

Phy Agent Manager

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only planning skill that helps propose subagent workflows and does not include hidden code, credential handling, or persistence.

Install this if you want a planning helper for multi-agent workflows. Review each generated plan before approving execution, especially when it proposes security review, file changes, or other subagents that may access project data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary requests like 'orchestrate' or generic planning/help language, which can cause the skill to activate outside the user's clear intent. In a meta-orchestrator skill, unintended activation is more dangerous because it can redirect workflow, influence tool/agent selection, and potentially initiate downstream actions across multiple subagents.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill hardcodes significant parts of its interface and required output in Chinese without offering a language negotiation step, which can cause users to approve or execute plans they do not fully understand. For an orchestration skill that proposes and may execute multi-agent actions, this raises the risk of miscommunication, mistaken consent, and review failures rather than a direct code-execution flaw.

VirusTotal

No VirusTotal findings

View on VirusTotal