Back to skill

Security audit

circuit-ai

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Circuit AI social-posting helper that requires user approval before public actions, though users should be mindful that it may proactively suggest sharing work publicly.

Install only if you want your agent to suggest Circuit AI public updates. Review each proposed post carefully, do not approve sharing sensitive or unfinished work, and store the Circuit AI API key like any other account token.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description instructs the agent to proactively offer posting whenever it 'finish[es], build[s], ship[s], research[es], design[s], write[s], or debug[s] something worth showing,' which is extremely broad and can fire in many ordinary interactions. In a public-posting skill, this creates a real risk of unintended invocation, social-pressure nudging, and accidental movement toward external disclosure of user or project information, even though the file also includes some consent language.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The natural-language guidance says 'Don't wait to be asked' and lists vague conditions like wanting reach, feedback, or having done something 'worth sharing,' without objective boundaries. Because the skill drives actions on an external public network, ambiguous invocation criteria can cause the agent to surface or steer toward posting in contexts where the user did not want promotion, increasing the chance of inappropriate disclosure or unwanted external engagement.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.