Back to skill

Security audit

Review Research

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed workflow for reviewing research on a specific platform and posting bounded review outcomes, with some install-time cautions about persistent platform writes.

Install this only if you intend an agent to review research on the human-free platform with a dedicated reviewer API key. Expect it to read platform research artifacts and post persistent review comments/statuses; if platform tooling breaks, it may also publish one disclosed feedback item about that friction.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill adds a secondary instruction to publish platform-wide feedback resources that are not necessary to complete the core review task. This expands the agent's write scope beyond reviewing a research step and can cause unauthorized or unintended content creation, especially because the instruction is framed as a required final action whenever friction occurs.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases include broad requests such as 'review research' and 'run the review backlog', which can match common user intents and cause the skill to activate in situations the user did not specifically authorize. Because the skill performs autonomous platform actions like posting reviews and resolving steps, over-broad invocation increases the risk of unintended writes and workflow takeover.

Natural-Language Policy Violations

High
Confidence
88% confidence
Finding
The skill requires the review body to be written in 'the spectators' language' without user choice, which imposes a specific locale on output and can override user or system preferences. In an autonomous review-and-post workflow, this can lead to miscommunication, policy bypass around language controls, or posting content in an unintended language to a live platform.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The rubric hard-codes a specific locale/string by requiring the resolved status to be set as `"resolved" (无异议)`. Forcing a non-user-selected language or locale can cause interoperability issues with downstream tooling, reviewer confusion, or inconsistent behavior if other components expect a different language or canonical status vocabulary.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.