Back to skill

Security audit

java-coding-guide-pro

Security checks across malware telemetry and agentic risk

Overview

This is a Java coding-guidance skill with broad but disclosed activation and no hidden execution, persistence, or credential access.

Before installing, be aware that this skill may activate for most Java or Spring Boot coding tasks and influence style choices broadly. That appears intentional for a coding guide, but users who only want occasional standards advice may prefer a narrower trigger.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
94% confidence
Finding
The skill’s activation scope is extremely broad, effectively telling the agent to apply this skill to almost any Java or Spring Boot coding, modification, refactoring, or review task. Over-broad activation can cause inappropriate interception of unrelated requests, unnecessary file access for stack detection, and instruction overshadowing where this skill’s guidance dominates more task-specific or security-relevant skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.