Back to skill

Security audit

dispatching-parallel-agents

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed workflow guide for splitting independent debugging work across parallel subagents, with no hidden data access or destructive behavior found.

Install this only if you want your agent to use parallel subagents for independent debugging or test-failure investigations. Review the spawned tasks carefully, keep each agent scoped to separate files or subsystems, and verify all returned changes before integrating them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The file uses Indonesian in the manifest description and trigger engine text, which defines activation and operating instructions in a fixed language. There is no indication that the skill is region-specific or that users may choose another language, so this creates a language/locale policy concern.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.