Fec Alchemy

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow skill for adapting ideas from reference projects, with no executable code or hidden data handling found.

Install only if you want an agent to help compare reference systems against your project and produce original, project-native plans or changes. Because it encourages reviewing project and reference materials, use it with repositories and sources you are comfortable letting your agent inspect.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The package description is framed broadly enough to match many generic requests about improving architecture, workflows, quality systems, or engineering practices. In an agent skill ecosystem, overly broad activation language can cause the skill to be invoked outside its intended scope, increasing the chance that untrusted reference material influences unrelated tasks or that the skill overreaches into sensitive project decisions.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal