Back to skill

Security audit

Self-Discovery Reasoning

Security checks across malware telemetry and agentic risk

Overview

This appears to be a reasoning-helper skill, but it uses broad automatic activation and persistent memory in ways users should review before installing.

Install only if you are comfortable with a skill that may activate during ordinary high-importance prompts and may persist derived reasoning structures for future use. Review or disable memory-writing behavior if your tasks may involve sensitive goals, confidential projects, or private user context.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The line states that the skill 'activates automatically' to compose reasoning structures, but provides no narrow trigger conditions, scope limits, or user-consent boundary. Broad automatic invocation can cause the agent to apply hidden instructions to unrelated tasks, increasing the risk of prompt injection, policy override, or unintended behavior inherited from the referenced skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The line states that the skill "activates automatically" to compose reasoning structures, but it does not define clear triggering conditions, scope limits, or trust boundaries. Broad automatic activation can cause the agent to ingest and follow untrusted instructions from nested skill content for unrelated queries, increasing prompt-injection and unintended-behavior risk.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manual trigger phrases include very broad, everyday language such as requests to 'think carefully' or statements that something is 'important' or 'critical'. This can cause the skill to activate in many ordinary conversations without clear user intent, leading to unnecessary hidden behavior changes, extra processing, and unexpected reasoning-mode escalation.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to write discovered reasoning structures to persistent memory without notifying the user or obtaining consent. Even if the stored content is framed as reusable structure, it may contain sensitive task characteristics, user goals, or derived information that persists across sessions and creates privacy, retention, and cross-task data leakage risks.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.