Back to skill

Security audit

FDE Agent Skill Designer

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed skill-design and mock-POC scaffold helper, with local file generation only when explicitly requested.

Use this for designing skills and mock POC scaffolds from already-approved requirements. Review any generated files before installation, keep production credentials and real integrations out of the mock scaffold, and require explicit authorization before adding external write actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger 'Need to process bill explanation ticket' is broad and underspecified, which can cause the skill to activate in situations outside its intended scope. In a support environment, ambiguous invocation increases the chance the agent handles adjacent tasks such as refunds, disputes, or other sensitive billing actions without the stricter controls those flows require.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
assets/minimal-poc/poc-manifest.json:21