Automation Runner

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed automation helper, but it asks for shell execution, Bitwarden secret access, long-running process control, and persistent command-output logging without enough scoping or redaction detail.

Review before installing. Use only with a real enforceable approval gate, a command allowlist, narrow Bitwarden permissions, a sandboxed scripts directory, and logging rules that redact secrets and sensitive output or allow logging to be disabled.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly states that command output will be logged to a memory file, but the user-facing description does not warn about this data retention behavior. In a shell-execution skill that also retrieves secrets and handles system tasks, command output may contain sensitive data such as tokens, file paths, environment values, or operational details, so undisclosed logging increases privacy and security risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal