Skill Org

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only drafting skill for creating job descriptions and skill files, with no code execution, hidden access, or credential use.

Reasonable to install as a drafting aid. Review any JD or skill it generates before adopting it, especially because its broad triggers may activate during general workflow-design conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description includes broad trigger phrases such as helping write a skill, define responsibilities, solidify a method, split a workflow, or decide who should do a task. These are common everyday requests that can overlap with many other skills, increasing the chance of unintended invocation, prompt routing errors, and execution in contexts the skill was not designed for.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal