Back to skill

Security audit

Blind Review Sanitizer

Security checks across malware telemetry and agentic risk

Overview

This skill is a local manuscript anonymization helper with expected file access and no evidence of hidden network, persistence, credential, or destructive behavior.

Before installing, verify the DOCX dependency you intend to use, preferably pin it to a reviewed version, and run the tool only on intended manuscript files. Review the generated output manually because automated anonymization may miss document metadata, images, headers, footers, or indirect identity clues.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Unpinned Dependencies

Low
Category
Supply Chain
Content
docx
Confidence
97% confidence
Finding
docx

VirusTotal

42/42 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.