Checksum

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward local checksum tool; it can read files you point it at, but that behavior is disclosed and matches its purpose.

Install if you want a local checksum helper and understand that it can read files or directories you explicitly ask it to hash. Avoid directing it at sensitive files unless you intend to reveal their hashes, prefer SHA-256 or SHA-512 over MD5/SHA1, and use the package-root command path if the documented skills/checksum/index.js path does not exist.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

No VirusTotal findings

View on VirusTotal