Back to skill

Security audit

slop-check

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local codebase grading tool that scans source files, writes a local report, and serves it on localhost without evidence of exfiltration or destructive behavior.

Install if you want an opinionated local repo-quality grader. Be aware that it reads the target repository, writes report artifacts into it, may use several reviewers on larger repos, and can start a localhost-only report server; use it on code you are comfortable having summarized in local report files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
96% confidence
Finding
The invocation guidance is extremely broad and includes common requests like 'audit', 'report card', 'code quality score', and general code smells, which can cause this skill to activate in situations far beyond a user's explicit intent. That creates an overreach risk: the agent may run repository-scanning logic, generate files, or start local services when the user only asked for lightweight advice or a normal review.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal