nature-figure

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward scientific figure-making guide, with a caution that one shortcut references a separate local helper script not included in the reviewed package.

Reasonable to install for publication-style scientific plotting. If using the fast auto-figure command, verify that the referenced local helper script is present and trusted; otherwise ask the agent to generate transparent Python or R code and run it only on data files you choose.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list includes generic terms such as "figure," "plot," and "color palette," which can appear in many unrelated conversations. This can cause unintended activation of the skill, leading the agent to switch into figure-generation behavior when the user did not request it, increasing the chance of irrelevant actions or unsafe downstream tool use.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal