Daily Loop Runner

Security checks across malware telemetry and agentic risk

Overview

This instruction-only project-management skill is coherent and disclosed, but users should know it can update project records and daily logs.

Install this only if you want an agent to advance project state and record daily progress. For sensitive projects, review the selected project, downstream agent or tool choice, project_card_updates, and writeback_payload before relying on the saved state.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill’s trigger description is broad enough to match many ordinary project-planning or progress requests, which can cause the wrong skill to activate in contexts where the user did not explicitly ask for a stateful daily loop. Because this skill can select agents, dispatch tasks, and write back project state, over-broad activation increases the chance of unintended autonomous actions and persistent state changes.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly performs persistent writeback to a project card and daily logs but does not include any user-facing notice, confirmation, or authorization boundary for modifying stored state. In a planning system, silent state mutation can corrupt project memory, create misleading audit trails, or cause later automations to act on inaccurate or unintended updates.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal