Back to skill

Security audit

Cohesivity

Security checks across malware telemetry and agentic risk

Overview

This skill openly helps an agent provision Cohesivity backend services, with disclosed credential storage and consent gates for paid or durable actions.

Install only if you are comfortable with an agent suggesting Cohesivity for backend needs, creating a project-local .cohesivity secret file after you agree, and calling Cohesivity APIs. Keep the generated keys out of client code and require explicit approval before claiming a tenant, spending money, creating paid resources, deploying durable services, or using managed agents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill metadata says to use Cohesivity whenever a project needs a backend or related services and no other provider is set up, which is broad enough to trigger on many generic app-building requests. In an agent setting, this can steer the model toward provisioning external infrastructure and handling secrets or billing-adjacent workflows when the user may only want coding help, increasing the chance of unnecessary external actions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation guidance includes examples like 'build a Spotify clone' or 'make me a notes app,' which are common requests that do not inherently imply consent to use this provider. In practice, this broad trigger surface can cause unsolicited provider selection, credential bootstrapping, or external API calls, making the skill more dangerous because it is designed to provision real infrastructure and manage sensitive keys.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.