FullStack Developer

Security checks across malware telemetry and agentic risk

Overview

The skill is a broad full-stack engineering guide, but its behavior is disclosed and aligned with building web applications.

Install this as a general coding aid, not a narrowly scoped specialist. Review its suggestions before applying changes, and do not provide production credentials, payment-provider access, or deployment authority unless you explicitly intend the agent to work on those parts of your app.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation description is extremely broad and is designed to trigger on almost any request involving building, designing, or scaffolding software. This can cause the skill to activate outside a clearly bounded context, increasing the chance it overrides more specialized or safer skills and expands its authority over user requests in ways the user did not explicitly intend.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal