Tech And Internet Domain Search Agent

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only web research skill whose web access and wiki document writing match its stated reporting purpose, with some privacy caveats around saved research logs.

Use this for non-sensitive web research where saving a research log and final report is acceptable. Avoid private or confidential topics unless you know how the wiki documents are stored and deleted, and ask the agent to verify key claims across authoritative sources rather than trusting a single scraped page.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill is advertised with a very broad, generic description and no clear trigger boundaries, which increases the chance it will be invoked for unrelated tasks and apply its powerful research-and-write workflow in inappropriate contexts. In this file, that broad invocation combines with mandatory tool use and persistent document creation, making accidental misuse more likely rather than being a purely cosmetic issue.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The instructions require creating and appending to wiki documents as a default part of execution, but provide no user-facing disclosure or consent step for persistent storage. This can cause sensitive user queries, search results, URLs, or derived notes to be written to durable storage unexpectedly, creating privacy, data retention, and cross-session exposure risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal