Lucky Skill Creator

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent local helper for creating, validating, and packaging AgentSkill directories, with no evidence of hidden network access, credential use, or destructive behavior.

Safe to install for skill development. Use it only on intended skill folders, inspect generated templates and .skill archives before publishing, and avoid packaging directories that contain secrets or unrelated private files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The description trigger is broad enough to activate on many generic editing or packaging requests, which can cause this skill to be selected outside its intended niche. Over-triggering increases the chance that an agent follows self-modifying or shell-executing guidance in contexts where those behaviors were not expected, expanding attack surface and causing unsafe tool use.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal