Knowledge Bridge

Security checks across malware telemetry and agentic risk

Overview

This skill is a local knowledge-base bridge with disclosed ingest and backfill behavior, but users should review what local data it imports and retains.

Before installing, check that the referenced local insight-engine module and SQLite database path are yours and contain data you are comfortable retaining. Run ingest or backfill only intentionally, especially because backfill may import historical records, and plan how to inspect or delete stored entries if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill advertises automatic ingestion and backfill into a local SQLite knowledge base, but the user-facing description does not clearly warn that invoking it persists data to local storage at a specific path. This can lead to unintentional retention of potentially sensitive insight-engine outputs, larger-than-expected historical imports, and privacy/governance issues, especially because 'backfill' implies bulk writes across prior cycles.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal