Back to skill

Security audit

Cue Post Loan Monitoring

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Cue research workflow for post-loan monitoring, with no evidence of hidden persistence, exfiltration, or destructive behavior.

Install this only if you are comfortable with a Cue-based research skill that may clone or update the external cue-skills runner, use your local Cue API key, access public web/API sources, and spend Cue credits after confirmation. Review the external runner source if you need stricter supply-chain control.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger list is broad enough to activate on loosely related requests such as general due diligence, disclosure, or regulatory topics, which can cause the skill to run in contexts the user did not explicitly intend. In this skill, unintended activation is more concerning because execution may lead to external data fetching, repository cloning, and credit-consuming research workflows.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal