Back to skill

Security audit

sample-asset-skill

Security checks across malware telemetry and agentic risk

Overview

This is a small, non-executable sample skill that documents a PRD asset workflow and does not hide or automate risky behavior.

Before using the reproduction steps, confirm the target hub, account, visibility setting, and data being uploaded. Treat any real upload or form submission as an external side effect, even though this submitted skill itself is only documentation and sample content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly describes browser-driven upload, form filling, clicking, and screenshot steps against an external resource center, but it does not warn users that these actions can modify external systems or transmit data outside the local environment. This increases the risk of unintended data submission, accidental registration, or misuse of privileged browser sessions when the skill is invoked in automation-heavy contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.