Back to skill

Security audit

VC 大师指南

Security checks across malware telemetry and agentic risk

Overview

This is a Visual Components learning guide made of markdown documents, with no installer, executable code, credentials, or hidden actions.

Install this as a reference/tutorial skill for Visual Components. Treat the Python snippets and forum download references as learning material: verify against official documentation and be cautious before using forum attachments or applying scripts to real robot, PLC, or production workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrase for learning Visual Components basics is very broad and overlaps with ordinary user requests. In an agent environment, this can cause the skill to activate unintentionally and steer responses based on bundled skill content rather than explicit user intent, increasing prompt-injection and overreach risk.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The project-guidance example is open-ended and lacks constraints on domain, depth, or required confirmation, making it easy to match broad design-assistance requests. This can lead to unintended invocation and excessive reliance on the skill for generalized project planning beyond the user's explicit request.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.