Back to skill

Security audit

Context Doctor

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed, read-only context health checker, with only minor risk from broad trigger phrases that could invoke it unintentionally.

Install if you are comfortable with the agent reading session-level metadata such as token counts, tool-call counts, and tool-output sizes. Prefer explicit invocations like "context doctor" and avoid enabling optional automatic heartbeat checks unless you want periodic diagnostics.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrase “诊断” is very generic in Chinese and can easily appear in ordinary conversation unrelated to this skill. In a skill-routing system, such broad triggers can cause accidental activation, leading the agent to expose session metadata, spend tokens unnecessarily, or alter conversation flow when the user did not intend to invoke the skill.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The phrase “checkup” is a common English word and may collide with normal user requests, especially in mixed workflows where users discuss status, reviews, or diagnostics generally. This can trigger unintended execution of the skill, causing unnecessary context inspection and minor information exposure about session state.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes very common terms such as '诊断' and '健康检查', which can easily appear in ordinary conversation unrelated to this skill. That raises the risk of unintended invocation, causing the agent to enter diagnostic behavior when the user did not explicitly request it and potentially exposing session metadata or disrupting the normal task flow.

Vague Triggers

Low
Confidence
82% confidence
Finding
The activation guidance is broad and subjective, including conditions like '对话感觉变慢时' and periodic checking every 20-30 turns. These vague boundaries can make the skill trigger based on agent interpretation rather than explicit user intent, increasing the chance of unnecessary or unexpected execution.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.