qmd Search
Security checks across malware telemetry and agentic risk
Overview
This skill is a straightforward local search helper, with the main caution that it can index and retrieve local files through an external qmd command.
Install qmd only from a source you trust, understand where its local models and indexes are stored, and keep collections narrowly scoped so sensitive personal files, secrets, or private repositories are not accidentally searched or quoted by the agent.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
66/66 vendors flagged this skill as clean.
