12 Factor Apps

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only review skill for 12-Factor App compliance that uses normal local repository searches and does not request installs, persistence, credentials, or write access.

Install only if you want 12-Factor or cloud-native compliance reviews. Point it at the specific repository you intend to analyze, and treat raw findings about secrets, passwords, API keys, or database URLs as sensitive before sharing reports.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is broad enough to be invoked for many generic code review or architecture-review tasks, not just narrow 12-factor assessments. That can cause this skill to activate in contexts where its shell-oriented scanning guidance is unnecessary or risky, increasing the chance of over-collection, noisy analysis, or interference with more appropriate security-focused skills.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal