Hybrid Retrieval (BM25 + Vector + Graph)
Security checks across malware telemetry and agentic risk
Overview
This is an instruction-only skill for designing hybrid search systems, with no executable installer or hidden high-risk behavior found.
Install this if you want guidance for building a retrieval or RAG system. Before applying it to real data, decide which documents the agent may index, avoid sending sensitive text to cloud embedding providers unless approved, and manage API keys or database credentials outside shared chat context.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
