AI Task Companion

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only helper that recommends AI tools and can assist after user agreement, with no code, credential access, or persistence shown.

Installers should treat this as a planning and recommendation helper. Before letting it execute a recommended option, confirm which tool will be used, what information will be shared, and whether the action affects external websites, accounts, generated files, or public content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are so broad that they match ordinary conversation such as '帮我做...' and '我需要...', making accidental activation very likely. In this skill's context, unintended activation can lead to unsolicited tool recommendations or even downstream execution flows, which increases the risk of privacy leakage, unsafe automation, or user confusion.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly offers to 'directly help complete' tasks without warning that external tools may be invoked, data may be transmitted, or actions may have side effects. In a tool-orchestration skill, this omission is security-relevant because users may provide sensitive content or authorize execution without informed consent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal