Back to skill

Security audit

Logo Brand Identity Tool Free

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only brand identity design skill with some overbroad tool permission and troubleshooting language, but no hidden install behavior, persistence, credential handling, exfiltration, or destructive instructions.

Before installing, be aware that the skill requests exec permission despite being primarily a design prompt. Prefer using it for user-directed brand design tasks, and treat any network troubleshooting command as optional and something to approve deliberately.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill includes network troubleshooting guidance that instructs use of ping/firewall/proxy checks, which is unrelated to logo or brand identity design. In an agent context with exec capability, this broadens operational scope and can be abused to trigger unnecessary shell/network activity beyond the advertised design function.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill declares an overly broad trigger scope with generic phrases and weak constraints, making it easier for the agent to activate this skill in unrelated contexts. Over-broad activation increases the chance of unintended tool use, prompt collisions, and scope creep, especially because the skill is allowed to use exec.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.