Back to skill

Security audit

洞明

Security checks across malware telemetry and agentic risk

Overview

This appears to be a strategy-advice skill with overly broad activation wording, but no evidence of hidden data access, persistence, or unsafe actions.

Reasonable to install if you want a broad strategic-advice workflow. Review the trigger behavior first: because it can activate on implicit strategic intent, prefer using it only when you explicitly want a full strategic analysis rather than a lightweight business answer.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The metadata sets `trigger_mode` to include an implicit mode based on broadly defined 'strategic decision intent' without clear boundaries. This can cause the skill to activate for many ordinary business or analytical requests, increasing the chance of unintended takeover of conversations and misrouting to a high-authority chief-agent workflow.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The 'Use when' description enumerates many broad business topics such as market research, competition analysis, and organizational diagnosis, which overlap with common user queries. In a skill-selection system, this breadth can lead to overmatching and inappropriate invocation, especially because the skill claims a chief-agent role and comprehensive methodology.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The routing section explicitly allows implicit triggering on any expression of 'strategic decision intent' after confirmation, but does not define sufficient constraints or rejection cases. Because strategic intent can be inferred from many ambiguous business prompts, this increases the risk of accidental activation, conversation hijacking, and unnecessary loading of authoritative behavior patterns.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.