Back to skill

Security audit

Enhanced Prompt Suite

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-template-only skill, but it broadly covers medical, financial, legal, and destructive workflow advice without clear safety limits.

Install only if you want a very broad prompt-template library and are comfortable supervising it closely. Treat outputs in medical, mental-health, financial, legal, compliance, deletion, cancellation, write-off, and termination contexts as drafting or brainstorming only; do not let an agent use these templates to make decisions or take real actions without qualified human review and explicit confirmation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The manifest includes a long trigger list with broad, loosely bounded phrases such as generic prompt-suite terminology. In an agent environment, ambiguous activation terms can cause unintended invocation or make it easier for unrelated user input to route into this skill unexpectedly, increasing the chance of unsafe behavior in sensitive domains.

Missing User Warnings

High
Confidence
95% confidence
Finding
The medical and psychological sections present diagnostic, treatment, medication, and intervention templates as executable guidance without safety disclaimers, triage boundaries, or escalation rules. That can lead users to over-rely on unverified model output for health decisions, including crisis situations, causing real-world physical or psychological harm.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The financial and investment templates generate portfolio, strategy, and risk-model outputs without non-advisory disclaimers or suitability warnings. Users may treat generated content as personalized investment advice, creating financial-loss and compliance risk.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The legal, rights, contract, patent, and compliance sections offer structured legal-style outputs without warning users not to rely on them as professional legal advice. This can produce incorrect filings, contracts, or legal strategies and expose users to regulatory or litigation harm.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill includes data-destruction, archive-destruction, information注销, bad-debt write-off, and termination workflows with no safeguards, confirmations, or warnings. In an integrated agent setting, such destructive guidance can be misapplied or automated, leading to irreversible data loss, unauthorized account termination, or evidence destruction.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.