Back to skill

Security audit

deep-research-glim

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed deep-research workflow that uses web-oriented research tools and subagents, with no hidden install code, persistence, credential handling, or destructive behavior found.

Install this if you want an agent to run multi-source research using glim tools and multiple subagents. Expect it to make network queries and spend more time or tokens than a simple search. Use the explicit /deep-research-glim command when possible to avoid accidental activation from broad research phrasing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The description and invocation text allow activation on generic phrases such as "deep research" and "deep dive on," plus "any of the trigger phrases in the description." These phrases are broad enough to overlap with normal user requests and the file does not provide exclusion conditions or negative examples to bound when the skill should or should not activate.

Scope Creep

Low
Category
Excessive Agency
Content
Entity authorized to submit on behalf of the copyright owner. For the
purposes of this definition, "submitted" means any form of electronic, verbal,
or written communication sent to the Licensor or its representatives,
including but not limited to communication on electronic mailing lists, source
code control systems, and issue tracking systems that are managed by, or on
behalf of, the Licensor for the purpose of discussing and improving the Work,
but excluding communication that is conspicuously marked or otherwise
Confidence
70% confidence
Finding
not limited to

Scope Creep

Low
Category
Excessive Agency
Content
writing, shall any Contributor be liable to You for damages, including any
direct, indirect, special, incidental, or consequential damages of any
character arising as a result of this License or out of the use or inability to
use the Work (including but not limited to damages for loss of goodwill, work
stoppage, computer failure or malfunction, or any and all other commercial
damages or losses), even if such Contributor has been advised of the
possibility of such damages.
Confidence
70% confidence
Finding
not limited to

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.