Back to skill

Security audit

Volcengine Landing Zone

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly coherent for Volcengine landing-zone operations, but it requires saving a newly generated administrator password into a local Markdown file, which users should review before installing.

Install only if you are comfortable letting the agent perform confirmed cloud account, billing, identity, logging, and network changes. Keep the workspace private, do not commit or share generated output files, rotate the initial administrator password immediately after first login, and delete the password file once it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The manifest description is very broad and includes common verbs like analyze, consult, setup, manage, configure, or design across multiple cloud domains. This can cause the skill to activate for loosely related prompts and steer the agent into operational workflows the user did not specifically intend, increasing the chance of inappropriate file writes or infrastructure actions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The entry-routing table uses ambiguous trigger phrases and mandates automatic routing without first asking the user to choose a path. In a skill that can progress toward Terraform execution and account/network changes, underspecified routing raises the risk of misclassification and unintended progression into sensitive setup or recovery flows.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly requires writing the generated initial administrator password inline into a markdown file on disk, but does not require a clear warning, restricted storage location, or immediate rotation guidance beyond first-login change. Storing bootstrap credentials in a broadly readable workspace artifact increases the chance of credential exposure through source control, backups, shared folders, or later accidental disclosure.

Ssd 3

High
Confidence
98% confidence
Finding
The instructions mandate consolidating the freshly generated administrator password into a user-facing document and treat that document as the primary deliverable. In the context of an identity/bootstrap phase for a landing zone, this materially increases the risk of initial privileged credential disclosure, especially because the account receives AdministratorAccess and the file is likely to be retained, copied, or shared.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.