Back to skill

Security audit

deep-research

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed deep web-research workflow that creates cited reports, with broad but purpose-aligned research behavior and no hidden credential use or persistence.

Install this only if you want an agent to run broad web research, spawn multiple research sub-agents, and write local reports. Be especially careful with person, company, employee-complaint, and social-sentiment reports: keep the scope explicit, avoid private or identifying personal details, and treat forum or social claims as low-confidence unless independently corroborated.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill advertises very broad trigger phrases such as 'look into X', 'what's the deal with Y', and 'catch me up on X', which can cause the agent to invoke a high-autonomy web-research workflow for casual or ambiguous requests. In context, this is risky because the skill has broad web access, can fan out multiple sub-agents, and can perform due-diligence research on people or organizations, increasing the chance of unintended data gathering, cost, and privacy-sensitive analysis.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly supports research on a 'company or public figure' and broad due-diligence tasks, but the description provides no warning or safeguard around privacy, reputational harm, sensitive personal data, or high-risk allegations. In this context, the omission is material because the workflow encourages wide web collection and synthesis, which could amplify inaccurate, outdated, or sensitive information into a polished report without an upfront sensitivity check.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The file explicitly instructs broad application of the community research type using loose triggers such as 'something else' and 'load after the user confirms scope,' but it does not define meaningful exclusions or disambiguation boundaries. In an agentic system, this can cause over-activation or misrouting of user requests, leading the agent to gather unnecessary external information, expand task scope, or invoke parallel sub-agents when a narrower skill would be safer and more appropriate.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This guidance explicitly directs collection of 'employee complaints' from forums like Glassdoor and Blind and 'social sentiment' from Twitter/X, LinkedIn, Reddit, and HN, but it does not warn users that the output may include sensitive, reputationally harmful, low-confidence, or context-stripped claims. In a due-diligence skill focused on people and organizations, aggregating and summarizing such material can amplify unverified allegations or employment-related personal data, increasing privacy, defamation, and misuse risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.