Mlflow Experiment Tracker

Security checks across malware telemetry and agentic risk

Overview

This appears to be a purpose-aligned MLflow helper, with only a scoping caution around broad natural-language triggers.

Install only if you are comfortable having the skill help inspect MLflow experiments, runs, and metrics. When using it, give explicit experiment or run IDs and confirm the workspace/project context so the agent does not analyze the wrong MLflow target.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation phrases are broad and accept free-form identifiers/metric names without any stated scope limits, validation rules, or exclusions. In an agent setting, underspecified triggers can cause the skill to activate on ambiguous requests or process unintended MLflow experiments/runs, increasing the risk of data overreach, mistaken actions, or unsafe analysis on the wrong target.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal