Back to skill

Security audit

instant-execution-discipline

Security checks across malware telemetry and agentic risk

Overview

This skill is transparent about speeding up execution, but it should be reviewed because it can push agents to start tools, subagents, cron work, and persistent rule changes before clear approval boundaries are defined.

Install only if you want an agent to move quickly after explicit execution requests. Before using it for publishing, releases, public posting, financial work, account changes, cron jobs, or destructive operations, add a rule requiring confirmation for irreversible or externally visible steps. Also decide whether KPI logging to memory or Obsidian and permanent MISSION/skill updates are acceptable in your environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation trigger 'When the user requests execution, run this protocol' is extremely broad and can match a large share of normal user requests. In context, this broad trigger is paired with instructions to immediately launch tools before explanation, which increases the chance of unintended autonomous actions on ambiguous prompts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.