Back to skill

Security audit

Content Quality Auditor

Security checks across malware telemetry and agentic risk

Overview

This skill is a content-quality auditor with disclosed, purpose-aligned URL/content review and tightly limited persistence.

Before installing, expect the skill to fetch or inspect the specific content you ask it to audit and its cited/source controls. Only authorize persistence if you want an audit artifact saved under the stated memory path.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
84% confidence
Finding
Line L140 instructs the skill to 'Default to plain-language findings,' while the manifest also includes Chinese-facing naming and summary fields. This creates a natural-language policy concern because the skill sets an output-language default without explicitly offering user opt-in or language selection.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.