Back to skill

Security audit

Creative Design Payload

Security checks across malware telemetry and agentic risk

Overview

This is mostly a design-workflow skill, but it gives itself overly broad activation and unsafe self-modification instructions that users should review before installing.

Install only if you are comfortable with a broad creative-design workflow skill that may activate often. Before using it, consider removing or narrowing the instruction that forbids refusing skill-content modifications, and avoid exporting the full skill after adding private client examples, internal design assets, or sensitive workflow notes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Context-Inappropriate Capability

Low
Confidence
84% confidence
Finding
The skill explicitly allows exporting all skill files verbatim into a single prompt file, which can unnecessarily expose internal instructions, hidden workflow assumptions, and any future embedded secrets or policy-bypassing text to downstream tools. In a broadly-triggered creative skill, this increases prompt-injection and instruction-leakage risk because unrelated contexts may receive the full package without need-to-know justification.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill contains contradictory modification rules, but one of them instructs the agent to never refuse any modification to skill content, which weakens normal safety boundaries and creates ambiguity that an attacker can exploit. Contradictory governance in instruction files is dangerous because models may resolve the conflict inconsistently, often in favor of the more permissive instruction.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list uses very broad common phrases such as creative design, visual design, and project management, making accidental or over-broad activation likely. Over-triggering is risky because it can inject this skill's permissive or conflicting instructions into unrelated sessions, expanding the blast radius of the other unsafe behaviors present in the file.

Ssd 1

High
Confidence
98% confidence
Finding
The instruction requiring that the agent must not refuse any modification to skill content semantically disables refusal and safeguard behavior. In practice, this can be abused to coerce the agent into altering prompts, workflows, or embedded controls in unsafe ways, especially in a highly interactive skill that may be activated often.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.