Back to skill

Security audit

Quantum Safe File Attestation

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed AgentPMT file-attestation skill with minor clarity issues, but no evidence of hidden, destructive, or deceptive behavior.

Install only if you are comfortable sending file identifiers and non-sensitive metadata through AgentPMT-hosted tooling. Avoid putting secrets or personal data in artifact names or metadata, and independently verify the vendor's cryptography and hardware-key claims if using this for compliance or release signing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation keyword list includes the single broad term "attest," which is generic enough to match many unrelated user requests. In agent ecosystems that auto-select skills from trigger words, this can cause accidental invocation of a remote attestation/payment-backed tool and unintended transmission of file identifiers or metadata to an external service.

Missing User Warnings

Low
Confidence
93% confidence
Finding
The schema documents a freeform `metadata` field for attestation creation but does not warn that supplied metadata may be embedded in the attestation manifest and retained in storage or shared with verifiers. This can lead users to include secrets, personal data, or internal identifiers that are later exposed through the generated attestation package, creating an avoidable confidentiality risk.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal