Back to skill

Security audit

Critical Thinking

Security checks across malware telemetry and agentic risk

Overview

This skill intentionally edits a workspace AGENTS.md instruction file, but the behavior is disclosed, scoped, and requires explicit user approval.

Install only in workspaces where you want future agents to apply this decision-quality rule. Review the exact AGENTS.md path and block before approving, because the change can affect later sessions that load that file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Persistent Context Injection

Medium
Category
Memory Poisoning
Content
- the exact target path;
   - the exact rule block below;
   - whether the action will insert, replace an older equivalent block, or do nothing.
7. Obtain explicit approval before editing the persistent instruction file.
8. Preserve all unrelated instructions. Insert the block in the most relevant general-rules section; otherwise append it cleanly.
9. Re-read the file and verify that the block appears exactly once.
10. Report the changed path and explain that the behavior applies only when that AGENTS.md is actually loaded. Recommend verification in a fresh session when possible.
Confidence
95% confidence
Finding
persistent instruction

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.