Back to skill

Security audit

zayn-push

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only sales follow-up guidance skill with clear boundaries and no hidden execution, persistence, or data access behavior.

Before installing, treat any customer/project details you provide as potentially sensitive business information and review generated customer-facing wording before sending. The artifact does not show hidden automation or access requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The invocation template tells users to call PUSH() based on a very open-ended set of business inputs, but it does not define when the skill should not be used, what boundaries apply, or what exclusions exist. In an agent setting, broad triggers can cause over-invocation, inappropriate use on insufficient context, or use in sensitive situations where the skill's persuasion-oriented output could be misapplied.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.