Back to skill

Security audit

Agent Supervision

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple VeriClaw routing alias with broad trigger wording, but it does not run code, access data, or request privileged capabilities.

Safe to install with ordinary caution. Use it when you want VeriClaw-related agent supervision or QA routing, and be aware it may be selected for generic review phrases because its trigger wording is broad.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger `agent supervision` and the surrounding alias description are very broad, which can cause the skill to activate for many generic oversight, QA, or review-related requests that may not actually be about this specific tool. In an agent ecosystem, overly broad matching can misroute users, override more appropriate skills, and create prompt-scope confusion even if the content itself is not overtly malicious.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The invocation list includes highly generic phrases like `human review`, `LLM QA`, and `AI output QA` without qualification, so the skill may capture ordinary review requests unrelated to VeriClaw. This increases the chance of unintended routing and weakens user intent fidelity, especially in environments where skill selection is phrase-driven.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The routing rules explicitly collapse several umbrella intents into the same destination without defining boundaries, which can cause overbroad interception of unrelated supervision or review tasks. Because this file is an alias router rather than a narrowly scoped functional skill, the lack of limits makes ambiguous activation more dangerous in context.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.