Lobster Attachment Inject

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only helper for reading local agent and skill descriptions and optionally generating lightweight registry text, with no hidden code execution or data export found.

Install only if you are comfortable with the skill reading local agent and skill markdown files and helping create or update registry/prompt-context files. Review any generated AGENTS.md or registry changes before relying on them, especially in repositories containing private workflows or sensitive notes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation examples use broad natural-language phrases like "调度Agent" and "调试" as triggers without defining scope, precedence, or disambiguation rules. In an agentic system, vague trigger boundaries can cause unintended skill or file loading, which increases the chance of prompt-routing mistakes, unnecessary exposure of internal registries, or attacker-controlled phrasing steering the agent into unexpected behavior.

VirusTotal

52/52 vendors flagged this skill as clean.

View on VirusTotal