Back to skill

Security audit

Arya Model Router

Security checks across malware telemetry and agentic risk

Overview

This skill is a local model-routing helper that is disclosed, purpose-aligned, and shows no evidence of hidden data access or harmful behavior.

Install this if you want local help choosing model tiers to manage cost. Review the model names and thresholds in rules.json, use router auto off or explicit @cheap/@pro overrides when you want tighter control, and avoid sending sensitive context into generated briefs or sub-agents unless that is intentional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger "Router: analiza esto" is broad and underspecified, which can cause the skill to activate in situations not clearly intended by the user. In a routing skill that can recommend or execute sub-agents and potentially escalate to stronger models, ambiguous activation boundaries increase the chance of unnecessary delegation, token use, or unintended handling of sensitive context.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.