Back to skill

Security audit

tech-architect

Security checks across malware telemetry and agentic risk

Overview

This is a simple architecture-planning skill that only guides the agent to produce technical design documents and does not request sensitive access or execution authority.

This skill appears safe to install for architecture-design assistance. Users should be aware it may activate for broad Chinese architecture terms, so use more specific prompts when a different specialized skill is desired.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation description uses broad trigger terms like '技术架构', '技术方案', and '系统设计' without defining boundaries, exclusions, or required inputs. This can cause the skill to activate in overly broad contexts and steer the agent into producing architectural guidance when another specialized or safer skill would be more appropriate, increasing the chance of misrouting and unsafe or low-quality outputs.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.