Back to skill

Security audit

CI发布工程师 CI与发布门禁

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only CI and release-readiness checklist with no code, installer, credentials, or persistence.

Safe to install as an advisory CI/release-gating checklist. Treat its output as a structured review aid, not automatic release approval, and confirm project-specific CI requirements before relying on its recommendation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation conditions are broad enough to trigger on generic CI, pipeline, and release-readiness discussions, which can cause the skill to engage outside its intended scope. In an agentic system, ambiguous routing can lead to the wrong policy being applied, incomplete security review, or overconfident release recommendations based on mismatched context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.