Back to skill

Security audit

bug-review

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed bug-review workflow that may run local tests and suggest code fixes, with minor caution around broad triggers and expertise-style wording.

Install this if you want an opinionated bug-review workflow that reads project files, runs normal local verification commands, and prepares code/test changes. Be aware that its broad triggers may activate during routine development requests, and treat any stated expertise persona as review framing rather than a real credential.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes broad, common terms such as "bugs," "fixes," and "verification," which can cause the skill to activate in routine development conversations where the user did not explicitly request this workflow. Unintended invocation is risky because the skill encourages loading additional modules and running verification commands, increasing the chance of inappropriate context switching, unnecessary command execution, or exposure to adversarial repository content.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs the agent to present a fixed expertise persona to establish credibility, which can misrepresent the model’s real identity, qualifications, or lived professional experience. Even without malicious intent, this can create undue trust in the review output and may mislead users into overvaluing conclusions because they appear to come from a specific senior specialist rather than an AI system.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.