Back to skill

Security audit

Idea Generation And Ideation

Security checks across malware telemetry and agentic risk

Overview

This is a text-only ideation workflow skill that asks users to provide their own audience signals and does not install code, run commands, or take control of accounts.

Before installing, be mindful that the skill may ask you to paste real comments, DMs, FAQs, sales questions, or analytics signals. Use only information you are comfortable processing in your agent environment, and review generated idea banks before acting on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The description includes very broad, natural-language triggers such as being 'out of ideas,' 'stares at a blank calendar,' or thinking a niche is 'boring.' In systems that auto-route or invoke skills from conversational cues, this can cause the skill to activate unexpectedly, leading to incorrect task selection, context bleed from unrelated user requests, or unnecessary processing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.