Back to skill

Security audit

Prompt Architect Free

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a prompt-engineering template pack, but it includes unrelated shell/network troubleshooting instructions and broad activation language that warrant Review before installation.

Install only if you are comfortable with a prompt-engineering skill that has exec permission and contains an unrelated network troubleshooting instruction. Prefer revising or disabling the ping/firewall/proxy guidance and narrowing the trigger text before routine use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The skill is advertised as a prompt-engineering aid, but its error-handling table instructs the agent to run ping and inspect firewall/proxy settings when parameters are missing. That is unrelated to the stated task and can cause unnecessary command execution and system/network probing if an agent follows the document literally.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The documentation expands behavior from prompt design into network connectivity diagnostics, which exceeds the declared purpose of the skill. In an agent environment with exec enabled, this mismatch increases the chance of unintended shell execution or operational actions outside user intent.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Advising the use of ping plus firewall and proxy checks gives the skill system-administration behavior that is disproportionate to its prompt-engineering role. This broadens the operational surface area and may normalize privileged troubleshooting steps in contexts where they are unnecessary or unsafe.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger condition says to use the skill for broad needs like project management, task planning, progress tracking, and team collaboration, which is far wider than the skill's actual prompt-engineering functions. Overly broad activation criteria can cause the skill to be invoked in unrelated workflows, increasing the chance of inappropriate guidance or misuse of enabled tools.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.