Back to skill

Security audit

FDE Playbook Productizer

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation/playbook aid for turning validated delivery lessons into reusable assets, with disclosed boundaries and no executable install or persistence behavior.

Install only if you are comfortable giving the agent the delivery-review materials needed for productization. Use de-identified or authorized customer information, and treat any recommended public case study or reusable asset as requiring the review gates described by the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The handbook says skill assets should include triggers, workflows, tools, guardrails, assessments, and platform adaptation, but it does not define concrete trigger boundaries, approval criteria, or disallowed activation conditions. In a reusable agent-skill context, vague trigger guidance can cause a skill to run in inappropriate situations, increasing the chance of unsafe automation, overreach into sensitive tasks, or accidental invocation on customer-specific requests that should not be generalized.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.