Back to skill

Security audit

AI技能创建指南(免费版)

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only guide for creating AI skills, with no hidden execution, credential use, persistence, or data exfiltration behavior found.

This skill appears safe to install as a basic skill-authoring guide. Users should be aware that its own activation description is overly broad, so it may be invoked more often than intended; tightening the description and examples would improve quality but is not required for safety.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The frontmatter description is broad, repetitive, and frames the skill as generally applicable to 'related development scenarios' without clear boundaries on when it should or should not activate. In an agent ecosystem, vague activation metadata can cause the skill to trigger in unrelated contexts, injecting instructions and tool-oriented guidance unexpectedly.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The guidance says descriptions should include what the skill does and trigger scenarios, but it does not require negative constraints or specificity checks. That omission encourages authors to write expansive trigger metadata, which can lead to overbroad auto-activation and unintended influence over agent behavior.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example uses trigger phrases like '帮我旋转这个PDF' / 'rotate this PDF', which are common natural-language requests and can overlap with ordinary conversations outside a narrowly scoped skill-selection process. While the example is instructional rather than executable, it models a trigger style that may cause accidental activation if copied directly into real skill metadata.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.