Back to skill

Security audit

Skill Refactor

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only advisory method for evaluating and refactoring skills, with no code execution, credential access, persistence, or automatic changes.

Use this as a framework for reviewing skills, not as permission for automatic deletion or rewriting. Confirm the target skill and review any eliminate/refactor recommendation before applying changes, especially because its activation terms are broad.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are numerous and broad, including generic terms like '技能优化', '技能评估', and '技能整理', which can match ordinary user requests that are not actually asking to invoke this specific skill. Because this is a meta-skill that can restructure or eliminate other skills, accidental invocation increases the chance of unintended workflow takeover or inappropriate modification recommendations in unrelated contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.