deep-research-glim

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed deep-research workflow that uses web-oriented MCP tools and parallel subagents, with no artifact evidence of hidden persistence, credential access, destructive behavior, or exfiltration.

Install this if you want an aggressive deep-research workflow. Be aware that ordinary phrases like "deep research" or "deep dive on" may activate it, and once active it can spawn several subagents and query external sources; avoid invoking it on private or sensitive topics unless you are comfortable with that research context being used for the task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes broad phrases such as "deep research" and "deep dive on," which are common in ordinary user requests and can cause the skill to activate unintentionally. Because this skill instructs aggressive parallel tool use and multi-stage external research, accidental activation can lead to unnecessary external data access, higher cost, and unexpected behavior beyond what the user intended.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal