Back to skill

Security audit

STORM Research

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed research-planning prompt for content preparation and does not request commands, credentials, broad data access, or persistent background behavior.

Install this as a content-planning helper, not as a fact-checker or decision-maker. Use it to structure research questions and perspectives, then verify claims with primary sources before writing or relying on the output, especially for sensitive topics.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is broad enough to trigger on many generic research, writing, topic exploration, and product-question requests, which can cause unintended invocation outside the user's actual intent. In an agentic environment, overbroad routing can expose unrelated user inputs to this skill, create incorrect handoffs, and increase the chance of low-quality or unsafe research framing for sensitive topics.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.