Obv

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple local finance-reference helper that only prints bundled static guidance text.

Security risk appears low. Review the bundled shell script if you are cautious about local scripts, and independently verify any finance, regulatory, or investment-related content before relying on it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill's activation criteria are broad and generic for finance help, such as 'best practices,' 'troubleshooting,' and 'checklist or guide,' without tightly constraining what 'obv' refers to or when this specific skill should be invoked. This can cause the agent to select the skill for loosely related finance queries, leading to irrelevant or lower-quality guidance and increasing the chance of unsafe overreach in contexts where narrower, domain-specific skills should apply.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal