Skylv Agent Builder

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only agent template skill with no code, credential handling, network activity, persistence, or hidden behavior.

Safe to install as a reference/template skill. Review any generated agent blueprint before production use, especially where it proposes refunds, CRM updates, public posting, analytics access, or other external integrations, and use explicit user confirmation plus least-privilege credentials for any real implementation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to activate on ordinary conversation about agents, architecture, or templates rather than a deliberate request to invoke this skill. That can cause unintended skill execution, prompt/context hijacking of normal user interactions, and unexpected generation of agent blueprints that may override the user's actual intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal