Back to skill

Security audit

ALab Experiment Worker

Security checks across malware telemetry and agentic risk

Overview

This is a powerful but disclosed ALab project/experiment workflow skill, with credential and scope safeguards that match its stated purpose.

Install this only if you want Codex to operate ALab project or experiment workflows. Keep project admin keys in private environment variables or secure stdin, review destructive lifecycle actions before confirming them, and ensure worker sessions receive only experiment-scoped worktree tokens rather than admin or root credentials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables allow_implicit_invocation without any visible activation constraints, so the agent may invoke this capability based on loose relevance matching rather than an explicit user request. Because this skill can inspect worktree state, edit source, run evaluations, and submit experiment results, unintended activation could cause unauthorized code changes or submissions within the experiment context.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.