Nm Gauntlet Curate

Security checks across malware telemetry and agentic risk

Overview

This skill is a small, purpose-aligned helper for saving project knowledge annotations, with the main risk being expected local file creation.

Install only if you want the agent to create project-local annotation files. Review the generated YAML before saving, avoid putting secrets or private data in annotations, and remember that these files may affect future Gauntlet challenge context.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to generate and save a YAML file into the repository, but it does not clearly warn the user that it will modify workspace contents. This can lead to unintended repository changes, especially in automated or semi-attended agent workflows where users may assume the action is advisory rather than write-capable.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal