Back to skill

Security audit

Deep Research Executor

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only research helper whose browsing and report-writing behavior is disclosed and aligned with its purpose.

Install only if you are comfortable with the agent performing broad web research, using a subagent for source extraction, creating files in report/, and updating index.md. Review the generated report and citations before relying on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs the agent to create report files and modify index.md automatically, but it provides no requirement to obtain explicit user confirmation or clearly warn that files will be changed. In an agent environment, silent filesystem writes can lead to unintended persistence, workspace tampering, or modification of user content beyond what the user expected.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.