Back to skill

Security audit

AI Forensic Audit (Evidence Chain)

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only AI forensic audit guide with no executable behavior, though its broad trigger words could make it activate more often than intended.

Installers should understand that this skill may be invoked for broad audit or provenance requests. Use it when you intentionally want an AI evidence-chain report, and avoid providing sensitive logs or personal data unless they are necessary for the audit scope.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill metadata includes a long trigger list with broad generic terms such as '审计', '证据链', '追踪', and 'audit'. In platforms that auto-invoke skills based on keyword matching, these common terms can cause accidental activation in unrelated conversations, potentially exposing sensitive user content to this skill's audit workflow or interfering with intended tool routing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.