Back to skill

Security audit

Cloud

Security checks across malware telemetry and agentic risk

Overview

This is a read-only consumer cloud storage advice skill with some broad trigger phrases but no hidden, destructive, or credential-seeking behavior.

Installers should be aware that this skill may activate on broad file or cloud-related requests. Review its advice before acting on sharing, cleanup, cancellation, or backup recommendations, especially for sensitive documents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
95% confidence
Finding
The activation phrases are very broad and map to common, everyday support requests such as 'share folder' or 'where are my files.' In an agent environment, overbroad triggers can cause the wrong skill to activate unexpectedly, exposing user file-management context to a skill in situations where the user did not clearly intend it and increasing the chance of unsafe or privacy-impacting actions.

Vague Triggers

High
Confidence
94% confidence
Finding
The keyword list ('sync, cloud, organize, choose, share') is highly ambiguous and overlaps with ordinary language far beyond consumer cloud storage. In a multi-skill agent, this can lead to unintended routing, causing the skill to engage on unrelated prompts and potentially influence decisions about personal files or sharing behavior without sufficient user intent confirmation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.