SKILL Sonar

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only safety guard that adds review and confirmation checks, with no code execution, credential use, installation scripts, or external data transfer shown.

Install if you want stricter safety checks around skill review and runtime actions. Expect extra warnings, replanning, or confirmation prompts for sensitive files, tool use, code execution, external calls, deletion, and memory writes. The artifacts do not show automatic execution or data transfer, but the guard may slow workflows because it is intentionally cautious.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger condition 'If any trigger is detected, enter guarded mode immediately' is broad and does not clearly define what qualifies as a trigger at activation time. In a guard skill, underspecified activation can cause inconsistent enforcement across turns or actions, creating gaps where risky operations may proceed without the intended triage and confirmation steps.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal