Ai Act Risk Check

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrow AI Act risk checker, but users should know their entered description is sent to the configured Gemini CLI provider.

Install only if you are comfortable using the Gemini CLI for this check. Treat the AI-system description you type as data that may leave your local environment, and remove confidential business, personal, legal, or regulated details unless your Gemini account and data terms are appropriate for that use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The script sends user-supplied AI system descriptions to the external `gemini` CLI for inference without clearly warning the user that their input will leave the local environment. If those descriptions contain confidential, regulated, or personal information, this can cause unintended data disclosure to a third-party service and create privacy, compliance, or contractual risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal