Back to skill

Security audit

Ensure Docs

Security checks across malware telemetry and agentic risk

Overview

This documentation skill is purpose-aligned, but users should know it can edit documentation and agent-instruction files unless they ask for report-only mode.

Install only if you want an agent that may inspect documentation across the repository and make focused documentation, AGENTS.md, CONTRIBUTING.md, or compatibility-symlink changes. Ask for report-only mode when you want an audit without file edits, and review any changes to agent-instruction files because they can affect future agent behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow explicitly instructs the agent to apply edits to source files during documentation generation, but the skill does not require a clear upfront warning that files will be modified before entering that phase. In an agent setting, this can lead to surprising or unintended repository changes, especially if the user expected an audit-only operation or did not understand that generation would write directly to code files.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.