Cca Domain5

Security checks across malware telemetry and agentic risk

Overview

This is a CCA study skill with no artifact-backed evidence of hidden, destructive, credential-seeking, or exfiltrating behavior.

Reasonable to install as a study aid. Invoke it with specific CCA-related phrasing such as cca-domain5, and review any requested file edits, shell commands, or agent-spawning exercises before allowing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill metadata says it should be used when the user mentions broad phrases like “上下文管理” or “可靠性,” which are generic concepts that may appear in many unrelated conversations. This can cause unintended invocation of the skill, leading the agent to switch into tutoring behavior or apply domain-specific guidance when the user did not actually request this skill, reducing reliability and potentially interfering with correct task handling.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal