Back to skill

Security audit

Faers Multi Drug Soc Planner

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only FAERS study-planning skill with no code, credential access, persistence, or hidden system behavior.

Install this only if you want help designing FAERS/OpenFDA comparative drug-safety studies. Treat its output as research-planning guidance, not medical advice or proof of causality, and separately review any downstream data-analysis code or tools used to execute the plans.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger text contains broad catch-all language such as "or any phrasing like..." and "Always use this skill when users want...", which can cause the skill to be invoked for loosely related requests beyond its intended scope. In an agent system, overbroad routing can override more appropriate tools, leading to incorrect task handling, unintended disclosure of sensitive user context to this skill, or unsafe downstream actions based on mismatched assumptions.

VirusTotal

51/51 vendors flagged this skill as clean.

View on VirusTotal