Back to skill

Security audit

First Principles Reasoning

Security checks across malware telemetry and agentic risk

Overview

This is a single-file reasoning workflow that does not request system access, credentials, persistence, or command execution.

Install this if you want the agent to use a first-principles reasoning format. Be aware it may activate for broader reasoning or strategy prompts than expected; narrow or disable it if you only want the workflow used when explicitly requested.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The activation criteria are very broad and include many common reasoning requests such as challenging assumptions, reasoning from scratch, or sanity-checking defaults. In an agent system that auto-selects skills from natural language, this can cause the skill to trigger far outside a narrowly intended scope, potentially overriding more appropriate domain-specific skills and steering responses with an unintended methodology.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.