Back to skill

Security audit

contradiction-analyzer

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only analysis skill that changes how the agent structures multi-source debate research, without hidden access, credentials, or executable behavior.

Install this if you want the agent to frame complex or controversial research around contradictions, source stances, and credibility. Expect it to influence some broad discussion prompts, and verify the exact skill directory path before using the uninstall deletion commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The uninstall section provides irreversible directory deletion commands but does not warn users that the commands permanently remove files without confirmation. Even though the paths are scoped to the skill directory, destructive shell commands in installation docs increase the risk of accidental data loss from copy/paste mistakes, path expansion issues, or user modification.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger conditions are broad enough that the skill may activate for many ordinary multi-source or open-ended queries, causing unnecessary behavior injection into unrelated tasks. In an agent setting, overbroad activation can distort responses, increase prompt-scope creep, and bias analysis even when contradiction mapping was not requested.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.