Gatling AI Resource Manager

Security checks across malware telemetry and agentic risk

Overview

This skill is a local file-resource indexing helper with disclosed read/write needs and no evidence of hidden upload, destructive behavior, or automatic broad disk scanning.

Before installing, confirm you are comfortable granting local file read/write access for approved folders and scheduled daily card generation. Keep the output folder scoped, review generated cards before reusing their agent instructions, and avoid approving broad project roots that contain sensitive files unless you want them indexed as local resource paths.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The instruction text tells an agent to open a local project directory and then continue processing based on a future user request, without defining scope boundaries or allowed follow-up actions. In an agentic environment, this broad handoff can enable unintended file enumeration, disclosure of sensitive project contents, or unsafe downstream actions if later prompts are ambiguous or malicious.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal