Back to skill

Security audit

Project Onboarding

Security checks across malware telemetry and agentic risk

Overview

This skill is a repository onboarding guide that reads ordinary project files to summarize how a developer can start working safely.

Install this if you want an agent to inspect a project workspace and produce an onboarding guide. Be aware that broad trigger phrases may activate it for general project-start questions, so confirm the target project before letting it analyze a private or large repository.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger list contains broad phrases like '如何开发', '开发流程', and 'how to onboard', which can match many ordinary requests and cause this skill to activate outside its intended scope. Over-broad invocation can steer the agent into reading repository files and producing project-analysis workflows in contexts where the user did not intend that behavior, increasing the risk of prompt-surface expansion and unintended data exposure from the current workspace.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.