Benos Bootstrap

Security checks across malware telemetry and agentic risk

Overview

The skill does not appear to run harmful code, but it advertises real environment validation while its executable always reports success.

Treat this as Review rather than malicious. Install only if you understand it is effectively a placeholder and should not be relied on as a real bootstrap, health check, or safety gate until the advertised validation logic is implemented or the documentation is corrected.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Low
Confidence
84% confidence
Finding
The markdown says the skill is invoked "during startup or manually when system validation is required" and gives the example "Run benos-bootstrap," but it does not define specific trigger phrases, scope limits, or exclusion conditions. That ambiguity could cause unintended invocation because "system validation is required" is a broad condition rather than a precise activation rule.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal