Nm Pensive Test Review

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed test-review guidance skill with normal repository inspection and test/coverage commands, not hidden or destructive behavior.

Install this if you want help reviewing tests and coverage. Use it in repositories you trust or in a sandbox when running suggested test, coverage, or install commands, and review any evidence logs before sharing them because they may include local paths, command output, or project details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes very generic terms such as 'testing', 'coverage', and 'quality', which are likely to match ordinary developer conversations unrelated to explicitly invoking this skill. Overly broad activation increases the chance of unintended skill execution, causing unnecessary repository inspection or command suggestions in contexts where the user did not ask for this behavior.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal