Back to skill

Security audit

Brainstorming.Conflict

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only brainstorming skill whose repository-reading and design-document commit steps are disclosed and aligned with its planning purpose.

Install this if you want a structured design workflow. Before using it, be aware that it may inspect your repository context and may create and commit a local design document; review any generated file and commit before pushing or sharing your repository.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill uses broad mandatory language ('You MUST use this before any creative work') that can cause the agent to invoke it for a wide range of normal development activities. This creates an over-broad interception point that may unnecessarily steer workflows, consume context, and pressure the agent into following the skill even when it is not appropriate or explicitly requested.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to write a file under docs/plans and commit it to git without requiring explicit user approval or warning that repository state will be modified. In an automated or loosely supervised flow, this can lead to unintended file creation and version-control changes that the user did not consent to, especially because the skill is framed as mandatory.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.