Agent Performance Profiler

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only agent performance profiling skill, with no executable installer or credential request, but its automatic trigger wording is broader than ideal.

Install only if you want an agent-performance profiling prompt. Prefer manual invocation or narrower trigger settings, and avoid running it over sensitive conversations or tool traces until you know what data the host agent exposes to skills and whether profiling reports are stored.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger set is broad enough to activate on ordinary discussion of performance, optimization, tokens, or latency, which can cause unintended skill invocation. In an agent environment, overbroad activation can alter routing, inject irrelevant instructions into unrelated conversations, and increase the chance of prompt-surface abuse or operational confusion.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal