Back to skill

Security audit

Chief Pitfall Officer

Security checks across malware telemetry and agentic risk

Overview

This advisory skill is not malware, but it asks the agent to automatically persist user-derived business context and use stored instructions to change future runs.

Install only if you are comfortable with the skill attempting to keep local logs and evolve its own reference material. Do not enter confidential business details unless you can control where the skill is installed, review any files it writes under learnings/, and disable or ignore automatic vNext seed loading if you do not want prior conversations to influence future runs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill instructs the agent to autonomously persist new knowledge, update reference files, and generate future execution seeds that alter later behavior. That creates an unauthorized self-modification loop for a consulting skill, allowing untrusted user-derived content to become durable instructions and expanding behavior beyond the skill’s stated advisory scope.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
These instructions direct the agent to rewrite reference files and inject 'vNext' seeds into future runs, which is context-inappropriate for a procurement/risk-advisory assistant. In practice, this is a prompt-persistence and instruction-injection pathway: crafted user input can be transformed into stored guidance that silently influences subsequent executions.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrases are broad, everyday expressions such as '帮我理理需求' and '怎么落地', which can cause accidental activation in unrelated conversations. Unintended invocation increases the chance that the skill runs its heavy workflow, including risky logging/persistence behaviors defined elsewhere in the file.

Ssd 3

Medium
Confidence
92% confidence
Finding
The skill establishes an automatic retention pattern for runtime logging and knowledge extraction without clear minimization, retention limits, or separation between user content and reusable knowledge. Even with a warning not to provide PII, users may still disclose sensitive business details that would then be durably stored.

Ssd 3

Medium
Confidence
96% confidence
Finding
This section requires the agent to append conversation-derived metadata to a persistent runtime log after every interaction. Persistent storage of industry, scenario, referenced modules, and future feedback placeholders can expose confidential business context and creates an unnecessary audit trail from untrusted conversational input.

Ssd 3

Medium
Confidence
97% confidence
Finding
The knowledge-delta workflow explicitly mines user dialogue for prices, regulations, tactics, and industry details and writes them into persistent files. This creates a data poisoning and confidentiality risk: inaccurate, adversarial, or proprietary user-provided information can be promoted into the skill’s knowledge base and later reused as if trusted.

Ssd 3

Medium
Confidence
98% confidence
Finding
Active vNext seed generation and automatic reinjection create a durable prompt-injection channel across sessions. User-influenced instructions can persist as 'active' seeds and be injected into future executions, allowing one interaction to shape later behavior in ways that are difficult to audit or contain.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.