Back to skill

Security audit

super-intelligence-skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed reasoning and style guide with no executable code, credential access, or hidden data handling.

Install this only if you want broad reasoning, planning, and self-review behavior to influence complex tasks. Review the Indonesian instructions first, especially the optional SOUL.md persona guidance, because it may change response style and verbosity across agents where you enable it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation description is overly broad and can match many normal requests such as 'analisis mendalam' or 'rencana multi-langkah', causing the skill to trigger far more often than necessary. Over-broad activation increases the chance that its stronger instruction set influences unrelated tasks and expands the prompt-injection surface of the agent.

Natural-Language Policy Violations

High
Confidence
86% confidence
Finding
The skill is written entirely in Indonesian and frames its operational instructions in that locale without any user-language negotiation. While not directly enabling code execution or data exfiltration, forcing a locale can degrade user understanding, reduce oversight, and increase the chance of misunderstood safety-relevant behavior.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file explicitly instructs the agent in Indonesian and imposes a language/style regime across the entire persona layer without any user opt-in or locale gating. While not directly enabling code execution or data exfiltration, this can override user language expectations, reduce transparency, and create prompt-control conflicts that affect safe and accurate interaction behavior.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.