Agent Debate

Security checks across malware telemetry and agentic risk

Overview

The skill materials are mostly coherent maintainer/developer workflows, but one bundled review helper defaults to running a nested Codex review with full sandbox bypass and can automatically send diffs to fallback external reviewers.

Install only if you trust the publisher and want repo-maintainer automation. Before using `$autoreview`, prefer `--no-yolo` or `AUTOREVIEW_YOLO=0`, and review whether fallback external reviewers are acceptable for your private diffs. Use moderation and PR publishing workflows only with explicit targets and after checking the exact commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal