Back to skill

Security audit

Deep Research Pro v2

Security checks across malware telemetry and agentic risk

Overview

This is a coherent deep-research skill that searches public sources and writes local research reports, with no evidence of hidden credential use, destructive behavior, or exfiltration.

Install only if you are comfortable with research topics and derived keywords being sent to external public sources, and with reports and source lists being saved locally. For confidential or regulated work, explicitly limit sources, choose the output directory, and verify important conclusions before relying on the generated report.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The auto-activation condition is broad enough to trigger on many ordinary user requests about research, market analysis, or papers without a clear opt-in. In an agent environment, this can cause unexpected execution of a multi-step workflow with file creation and network retrieval, expanding the skill's authority beyond what the user explicitly authorized.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The listed natural-language triggers are common conversational phrases and can match benign everyday requests unintentionally. Because this skill performs extensive retrieval and writes structured outputs, accidental activation could lead to unanticipated network access and filesystem changes.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill mandates creation of multiple files and directories but does not disclose this behavior to the user at activation time. Silent filesystem writes are risky because they can overwrite existing content, leak sensitive research topics into local storage, or create persistent artifacts the user did not expect.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill performs outbound retrieval from APIs, websites, government sources, and patent databases without an upfront network access warning. This is dangerous because user queries may contain sensitive topics, and automatic transmission to third parties can expose confidential interests or operational context.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.