Skylv Data Analyzer

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward data-analysis skill for user-provided CSV/JSON files, with no hidden installer, persistence, credential use, or exfiltration behavior found.

Before using this on important data, keep an original copy and ask the agent to preview changes or write cleaned results to a new file. Avoid providing sensitive datasets unless you are comfortable with the local agent reading and analyzing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger list includes broad terms such as "data analysis" and "data insights," which can cause the skill to activate for generic requests beyond the user's specific intent. Over-broad activation increases the chance of unintended file access or analysis workflows being invoked when a different tool or safer interaction was expected.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly describes performing data cleaning actions, including deleting values, filling missing data, and replacing outliers, but does not warn that these operations may alter user data. If executed directly against source files, this can lead to silent data corruption, loss of original records, or irreversible modifications without informed consent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal