Back to skill

Security audit

Smart Router Publish

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed model-routing helper that may activate often, but the reviewed artifact does not show hidden access, destructive behavior, or data exfiltration.

Install this if you want the agent to consult a local router for many non-trivial prompts and show model-switch recommendations. Review the external smart_router/Ollama setup before use, and expect occasional over-activation from broad trigger phrases.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad natural-language phrases such as 'switch to', 'routing', 'what model', and 'which model' that are likely to appear in ordinary conversation. This can cause unintended activation of the skill, which then injects routing instructions into the agent workflow and may alter model-selection behavior without the user's explicit intent.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
86% confidence
Finding
The trigger phrase 'save cost' overlaps with the built-in command namespace because it begins with 'save'. In systems with prefix or fuzzy trigger matching, this can shadow or interfere with command parsing, causing the router skill to activate when the user intended a native save-related command, potentially changing agent behavior or suppressing the intended action.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.