Axiom Distributed Science

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only skill for querying a public science API, with a clearly documented optional submission endpoint.

Install this only if you want an agent to query Axiom's public science APIs. Before using the suggestion endpoint, confirm that the experiment idea and author name are safe to send to axiom.heliex.net, and do not include secrets, private research details, or personal data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill advertises very broad invocation conditions such as general scientific research, distributed computing, and curiosity about AI-driven research platforms. That can cause the agent to activate this skill for loosely related prompts and send user queries to an external service without a narrowly scoped user intent, increasing the chance of unnecessary data disclosure or unexpected tool use.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal