Back to skill

Security audit

Infinite Research Loop

Security checks across malware telemetry and agentic risk

Overview

This skill does not look clearly malicious, but its main loaded instructions do not match the advertised research-loop purpose and include broad workflow and memory behavior users should review first.

Install only if you are comfortable with a broad reasoning workflow that may influence many tasks and may try to retain preferences or lessons. The publisher should align SKILL.md with the Infinite Research purpose, narrow activation triggers, remove unrelated skill-creator instructions, and add explicit limits for memory behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill declares it is 'automatically engaged' for broad conditions like in-depth research, verification, debugging reasoning, or ensuring accuracy, without clear boundaries or explicit user consent. In a skill system where skills can alter agent behavior, this can cause unexpected takeover of normal workflows, interfere with safer or more specific skills, and increase the chance that adversarial or poorly scoped instructions shape responses more often than intended.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The description says the skill should be used for 'any modification or improvement request' and that it 'MUST first read this skill and follow its update workflow instead of editing files directly.' That trigger scope is excessively broad and can cause the skill to activate for many unrelated edit tasks, potentially overriding safer, more specific workflows and steering the agent into unnecessary file operations.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The checklist explicitly instructs the agent to document recurring user preferences, store validated insights, and assign memory priority without any requirement to obtain user consent, disclose retention behavior, or limit what may be stored. In a skill-creation context, this can normalize persistent collection of user-derived data across skills, increasing privacy, data-minimization, and policy-compliance risk if sensitive or unnecessary information is retained.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The prompt defines a broad operating mode and a 'master loop' without clearly scoping when these instructions should apply or how they interact with higher-priority system or runtime controls. In an agent setting, this ambiguity can cause persistent prompt behavior, unintended self-directed actions, or over-application of the skill beyond the intended task, increasing the chance of unsafe autonomy or instruction conflicts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.