Back to skill

Security audit

Trade Qualifier

Security checks across malware telemetry and agentic risk

Overview

This is a lightweight B2B customer-scoring skill with no executable payload or hidden data flow, though its trigger wording is broader than ideal.

Reasonable to install for B2B trade lead scoring. Use it with business data you are comfortable sharing with your agent, confirm ambiguous customer-scoring requests before applying it, and ask the publisher to clarify or remove the unexplained curl requirement if you require tight dependency hygiene.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger conditions are broad enough to match many ordinary requests about scoring, prioritizing, or analyzing customers, which can cause the skill to activate unexpectedly. In an agent environment, overbroad activation can hijack user intent, route data into the wrong skill, or produce actions and outputs the user did not explicitly request.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example phrase is highly generic and resembles normal conversation, so it could be used by the router as a broad activation cue far beyond the intended context. This increases the chance of accidental invocation and misapplication of the skill to unrelated customer-scoring tasks.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.