Back to skill

Security audit

observability-and-in

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a broad automation template for observability work, but it asks for read and command-execution capability without clear limits or user controls.

Review this carefully before installing. It does not show evidence of deception or exfiltration, but because it can guide an agent to read files and run commands, only use it in a workspace where you are comfortable with code inspection and command execution, and require explicit confirmation for API credentials, file changes, installs, and shell commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation description is extremely broad, framing the skill as suitable whenever users want efficiency, automation, batch processing, or workflow optimization. That can cause the agent to invoke a skill with file access and command-execution capability in contexts far outside observability work, increasing the chance of unintended system actions or sensitive data handling.

Vague Triggers

Low
Confidence
85% confidence
Finding
The phrase 'Use...' is left incomplete and ambiguous, so invocation conditions are not well specified. In an agent ecosystem, vague triggers can lead to accidental selection of this skill for unrelated requests, which is risky because the skill advertises operational capabilities including exec and automation.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill describes API credential setup, file processing, and command execution, but does not present clear user-facing warnings about side effects, data exposure, permission requirements, or system modification risk. Because the declared tools include read and exec, users or orchestrators may authorize impactful operations without understanding that secrets, local files, or host state could be affected.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.