Back to skill

Security audit

Arya Model Router

Security checks across malware telemetry and agentic risk

Overview

This is a local model-routing helper whose behavior is disclosed and aligned with saving token cost, with only minor guidance needed around explicit invocation.

Install this only if you want your agent to make routing recommendations and possibly use higher-cost models or sub-agents. Use explicit router prompts, and review rules.json/state.json if cost control or model-selection behavior matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger phrase "Router: analiza esto" is overly broad and can cause unintended auto-invocation for many normal user requests that merely include similar wording. In a routing skill, ambiguous activation is risky because it can silently alter model selection, invoke sub-agents, or change cost/privacy behavior without clear user intent.

Vague Triggers

Low
Confidence
88% confidence
Finding
The command triggers use plain natural-language phrases such as "router auto on", "router auto off", and "router status" with no namespace, prefix, or structural guard. This can cause accidental activation when ordinary user text includes those phrases, leading to unintended mode changes or disclosure of router state rather than an explicitly requested command.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.