Back to skill

Security audit

Agent Experience Graph

Security checks across malware telemetry and agentic risk

Overview

This skill is a local Python helper for recommending tools and skills from sanitized prior agent traces, with no evidence of hidden collection, network access, or destructive behavior.

Use this with trace libraries you trust and have sanitized. Do not store secrets, private customer data, proprietary snippets, or raw workspace content in shared traces, and disable implicit invocation if you do not want the skill automatically selected for recommendation tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation with no visible trigger constraints, exclusions, or scoping controls. For a skill that recommends tools and skills from prior agent traces, this can cause the system to invoke it in unintended contexts, potentially exposing prior execution context too broadly or allowing trace-derived recommendations to influence workflows without explicit user intent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.