Back to skill

Security audit

Generate Home Remodeling Company Client Education Handout

Security checks across malware telemetry and agentic risk

Overview

This is a simple handout-generation skill with no executable payload, hidden behavior, persistence, or credential use, though its Bash/Read permission and trigger wording are broader than necessary.

This skill is reasonable to install for generating remodeling-company client handouts. Review generated claims and visuals before publishing, and consider whether you are comfortable granting Bash and Read permissions since they are stronger than the described handout workflow appears to need.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill's activation guidance is overly broad, saying to use it for general client education work for remodeling contractors and renovation marketers without clear boundaries, prerequisites, or exclusions. Broad triggers can cause an agent to invoke the skill in contexts it was not designed for, leading to inappropriate content generation, scope creep, or unsafe automation decisions based on underspecified user intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.