Back to skill

Security audit

FDE Problem Discovery

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent problem-discovery helper, with some scope-drift and privacy-guidance gaps users should manage before relying on it for formal product planning.

Install only if you want a discovery-stage research assistant. Treat its outputs as discovery notes, not a PRD or implementation plan, and apply your own privacy rules for interview recordings, participant data, customer tickets, and business records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The file explicitly states it is 'used for pre-analysis before writing PRD' and frames its output as preparation for downstream product-definition work. That exceeds the stated skill boundary of problem discovery and can cause the agent to drift from evidence gathering into solution/requirements formulation, undermining scope controls.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The Y-model section explicitly says to 'reconstruct a better solution,' which instructs the agent to generate product solutions rather than stay in discovery mode. In this skill context, that is a meaningful scope violation because it can push the system into recommending designs or commitments that the manifest expressly forbids.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
Including 'How to implement' with front-end interaction and back-end logic introduces implementation design guidance into a discovery-only skill. This can steer outputs toward architecture or feature specification, which increases the chance of unauthorized solution design and conflicts with the skill's declared constraints.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
Recommending MVP or grayscale release testing moves beyond problem discovery into solution validation and experimentation. In this context, that can prematurely legitimize building or trialing solutions before the problem has been cleanly established, blurring governance boundaries between discovery and delivery.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The document says its abstract can be directly used as input for a PRD chapter, which directly contradicts the skill's instruction not to write a PRD. This makes the mismatch especially dangerous because it provides a concrete pathway for the agent to produce deliverables outside its authorized scope.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The interview guidance explicitly suggests obtaining recording permission, but it does not tell users how to handle recordings or interview notes containing personal data afterward. In a user-research skill, that omission can lead to unnecessary collection, insecure storage, excessive retention, or noncompliant sharing of participant data, creating privacy and regulatory risk.

VirusTotal

40/40 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.