Back to skill

Security audit

Ai Intelligent Asset Lifecycle

Security checks across malware telemetry and agentic risk

Overview

The reviewed package is a small descriptive asset-management skill with no embedded executable code, credential use, persistence, or hidden behavior.

Installing the reviewed skill appears low risk, but treat the documented GitHub clone and Python run steps as a separate trust decision. Review that repository and its requirements before running them, especially because the domain can involve business asset records and retirement workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest description is overly generic and does not clearly define the skill’s intended scope, triggers, or operational boundaries. In agent ecosystems, vague descriptions can cause inappropriate invocation, overbroad task matching, or misuse in contexts the author did not intend, increasing the chance of unsafe actions or privilege overreach.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal