Back to skill

Security audit

verification-criteria

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent requirements-engineering helper that reads user-supplied requirement/VC files and writes derived review artifacts, with no evidence of hidden exfiltration or destructive behavior.

Install only if you want an agent to process requirement and VC documents in your workspace. For large files, expect it to create split/merge outputs and possibly use subagents; review prompts before allowing overwrite/regeneration of existing VC files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
83% confidence
Finding
The declared description omits operational behaviors that modify files, create derived artifacts, and run splitting/merging workflows. That mismatch can mislead users and reviewers about the skill's real capabilities, increasing the chance it is invoked in contexts where file mutation or batch processing was not expected or approved.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger table uses very broad natural-language phrases such as "generate / write / 生成 VC," "audit / review / 评分," and "coverage / traceability / 覆盖率," which can cause the skill to activate on loosely related requests rather than explicit user intent to invoke this capability. In an agent environment, ambiguous activation increases the chance of the model loading domain-specific rules or processing sensitive requirement artifacts unexpectedly, creating prompt-scope confusion and unintended behavior.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The statement that the skill "auto-routes based on your phrasing" does not define clear activation boundaries, precedence, or disambiguation behavior. That ambiguity can let ordinary phrasing trigger this skill unexpectedly, especially in multi-skill agents, leading to incorrect routing, accidental file handling, or application of strict workflow constraints when the user did not intend to use this skill.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The file says to 'Load when a requirement has an ASIL level,' which is a broad activation rule for a safety-oriented pattern set. In an agent skill, loose triggering can cause this content to be injected into contexts where ASIL is mentioned but the user did not request safety-VC guidance, increasing prompt-scope creep and the chance of irrelevant or over-assertive safety recommendations influencing outputs.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.