Back to skill

Security audit

Compress

Security checks across malware telemetry and agentic risk

Overview

This skill is a text-compression prompt with some broad wording, but no hidden actions, persistence, data exfiltration, or destructive behavior were found.

Install this only for summarizing or semantically compressing text where small meaning changes are acceptable. Do not use it for exact records, credentials, medical instructions, legal terms, financial figures, or safety-critical material; also review any command execution before allowing it, since the declared exec tool is not clearly needed for ordinary compression.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
77% confidence
Finding
The trigger condition says to use the skill whenever the user needs 'Compress' functionality, which is overly broad and can cause the agent to invoke this skill in inappropriate contexts. In an agent environment with the exec tool enabled, over-broad routing increases the risk of accidental misuse, unsafe transformations of sensitive text, or invocation in contexts where lossy semantic compression is not acceptable.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.