双脑调度核心

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed orchestration prompt skill with no executable code, install hooks, persistence, credential access, or hidden data movement.

Install this only if you want a general multi-skill task orchestrator. Use it for complex coordination workflows, and keep sensitive credentials, private files, or unrelated prior outputs out of the context unless downstream skills genuinely need them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger conditions are very broad and ambiguous, including generic phrases like '协调多个Skill' and '任务编排', which can cause the orchestrator to activate for requests that do not actually require centralized routing. In this skill's role as the 'system唯一的调度与决策中心', unintended invocation is more dangerous because it can unnecessarily intercept tasks, influence routing decisions, and expand the amount of context exposed to downstream skills.

Ssd 3

Medium
Confidence
96% confidence
Finding
The skill explicitly requires passing complete prior outputs and key context to downstream skills and forbids sending only the minimal next action. This creates a built-in data leakage path: sensitive information, prior tool outputs, critic analysis, or unrelated context may be propagated to downstream components that do not need it, increasing confidentiality risk and cross-skill prompt/data exposure.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal