Back to skill

Security audit

math-review

Security checks across malware telemetry and agentic risk

Overview

This skill is a math-code review checklist that may run local tests and notebooks, but its behavior is disclosed, purpose-aligned, and not designed to steal data or make hidden changes.

Install this if you want agents to perform detailed mathematical and numerical review. Be aware that using it may run local tests, benchmarks, and notebooks in the target repository, so review notebook contents and test commands before execution in untrusted projects.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The manifest describes this skill as verifying math-heavy code for algorithmic correctness and numerical stability, which implies analytical review. However, the workflow instructs the agent to run shell commands like git inspection, pytest with benchmarks, and Jupyter notebook execution, adding code-execution capability that is not clearly justified by the stated purpose alone.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest trigger list contains generic terms such as "math," "algorithms," "scientific," and "ML models," plus the fragment "or numerical code." These overlap with common technical discussion and do not clearly constrain when the skill should activate, increasing the risk of unintended invocation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.