Back to skill

Security audit

Diting Training Expert

Security checks across malware telemetry and agentic risk

Overview

This is a training-advice skill with clear boundaries and no executable code, persistence, credential use, or hidden data movement.

Before installing, treat this as a workplace training-planning assistant. Review outputs before using them for HR decisions, especially where employee names, roles, assessments, budgets, or ROI estimates are involved. Route legal, compensation, performance-management, recruiting, and organization-design questions to the appropriate specialist instead of relying on this skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Low
Confidence
91% confidence
Finding
The direct-call fallback permits independent invocation when not routed through Chief, using only a loose requirement to 'define the training problem scope' and then proceed with the nearest scenario. This weakens routing controls and can cause the skill to answer broader workplace questions that should be handled by other specialists, increasing the chance of unsafe or policy-inconsistent guidance through scope drift.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.