Back to skill

Security audit

Design Thinking

Security checks across malware telemetry and agentic risk

Overview

This is a simple design-thinking prompt skill with no code, credentials, network access, or persistence behavior.

Install this if you want the agent to apply a structured design-thinking method. Be aware it may activate for broad product discovery or UX framing requests, so invoke it explicitly when you want that workflow and skip it for tightly specified implementation tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest description uses expansive trigger language such as applying the skill when the user wants broad human-centered exploration, reframing, or messy-context discovery. This can cause over-activation on loosely related requests, leading the agent to enter a design-thinking workflow when the user did not explicitly want it, which may derail task execution or unnecessarily expose more context to the skill than needed.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.