Back to skill

Security audit

Social Strategy

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent social media planning helper that reads relevant planning documents and writes a strategy file, with no hidden execution or sensitive access.

Before installing, be aware that a very generic phrase could activate this skill unexpectedly. Review any generated social-strategy.md for fit before using it, but the skill does not automate posting, access accounts, collect credentials, or run code.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrase "what's my plan" is broad and can match many unrelated user intents, causing the wrong skill to activate. In an agentic system, overbroad routing can lead to context confusion, unintended file reads, and generation of incorrect strategic artifacts for requests that were not about social media.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The eval case uses the input "Help me build a social media strategy," which is a broad natural-language phrase likely to appear in ordinary conversation. If skill routing relies on such broad triggers, the skill may activate unintentionally in contexts where the user did not explicitly intend to invoke this capability, leading to misrouting, unexpected file reads/runs, or inappropriate workflow execution. In this skill's context, that matters because it can cause the agent to pull in other skills and generate strategic artifacts without clear user intent.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.