Back to skill

Security audit

MUKI Asset Fingerprinting

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed red-team reconnaissance skill, but it can actively scan arbitrary targets and extract sensitive data, so it should be reviewed before installation.

Install only for authorized penetration testing or asset assessment. Before use, define written scope, target lists, rate limits, and data-retention rules; avoid scanning third-party systems; disable active or directory modules when not explicitly approved; and secure or delete reports containing credentials, PII, or financial data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
references/finger.json:24112