test

Security checks across malware telemetry and agentic risk

Overview

This is a text-only embedded firmware assistant with no install steps, executables, credential access, persistence, or hidden data flow.

Reasonable to install as an advisory firmware helper. Treat its code snippets as starting points, not production-ready firmware; in particular, add bounded timeouts or interrupt/DMA-based handling around polling examples before compiling or flashing to hardware.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation text allows the skill to be invoked by broad references to its name or general specialty, which can cause unintended routing or prompt injection through ambiguous mentions in normal conversation. Because this is a firmware-engineering skill with authority to produce implementation guidance, accidental activation could steer an agent into acting under the wrong persona or applying specialized instructions in contexts where they were not explicitly requested.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal