Back to skill

Security audit

Grit

Security checks across malware telemetry and agentic risk

Overview

This skill openly makes the agent more persistent and willing to try or install tools for blocked tasks, with no hidden code or install payload found.

Install this only if you want an agent to push harder on blocked work, try alternate tools, and potentially propose tool or skill installs. Use explicit invocation like "use grit" when you mean it, and review any proposed new tool, browser-session use, or API/CLI action before allowing it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest description contains broad activation phrases such as 'do whatever it takes', 'keep trying until it works', and 'never quit' that overlap with ordinary user language. This can cause the skill to trigger outside its intended scope, unintentionally escalating persistence, tool installation, or broader experimentation in situations where the user did not explicitly request this high-agency behavior.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal