Back to skill

Security audit

Communication Skill Free

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only communication drafting helper with minor overbroad/troubleshooting wording but no evidence of hidden access, persistence, exfiltration, or destructive behavior.

Installers should understand this skill is meant for drafting everyday text responses. Treat any network troubleshooting suggestions as manual platform troubleshooting, not as required skill behavior, and avoid relying on it for high-conflict negotiations, crisis communications, or sensitive legal/financial commitments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The skill is described as pure Markdown using only the read tool and explicitly says it requires no external communication, but its error-handling guidance later tells the agent/user to run ping and inspect firewall/proxy settings. That creates a capability/behavior mismatch that can lead an agent to perform unexpected network-related troubleshooting outside the stated trust boundary. In a supposedly read-only skill, hidden or contradictory operational instructions are dangerous because they normalize actions beyond the declared scope.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger condition is so broad that it can activate for ordinary communication requests across many contexts, increasing the chance the skill is invoked when not appropriate. Overbroad activation is risky because it can hijack general user workflows, override more suitable skills, or inject its instructions into unrelated tasks without clear user intent. The danger is amplified slightly because the skill presents itself as generally applicable across many agent platforms.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.