Marketing Strategy Domain

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a marketing-strategy reference library, but it tells the agent to automatically install another skill without explicit user approval.

Review this before installing if you do not want skills to add other skills automatically. The marketing content itself appears benign, but the dependency should ideally be installed only after you approve the exact `universal-task-os` source and version.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly instructs the agent to automatically install the `universal-task-os` dependency whenever it is missing, without requiring user confirmation or presenting any trust warning. Automatic dependency installation expands the attack surface, can introduce unreviewed code into the runtime, and is especially risky because the installed skill would gain influence over subsequent task execution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal