Back to skill

Security audit

Delivery Proof

Security checks across malware telemetry and agentic risk

Overview

This documentation-only skill coordinates delivery proof while explicitly keeping public, payment, contract, and account-changing actions behind fresh exact approval.

Before installing, understand that this skill is meant for workflows involving client delivery records and proof. Use it only where the agent has legitimate authority to handle the relevant private evidence, and keep external sending, publishing, payments, contracts, and account changes behind explicit approval as the skill requires.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
Plan`, private fulfillment preparation, any acquisition `Action receipt`, and
the available delivery or buyer-result context. Run Authorization permits
private deliverable creation, checking, evidence preparation, and correction
without asking for another approval. It never permits buyer-facing delivery,
publication, charging, contracting, or account mutation. If the acquisition or
delivery result has not arrived, record the awaited external result and return
to `moneyprinter`; do not invent it. Read `references/acceptance-and-proof.md`
Confidence
75% confidence
Finding
without asking

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.