Reference Maintainer

Security checks across malware telemetry and agentic risk

Overview

This skill is a local documentation generator, but it can preserve sensitive configuration or credential details in lasting reference files without clear scoping or redaction controls.

Install only if you want a tool that may read code or configuration files and write durable reference documents. Use it only on explicitly chosen paths, avoid secrets and credential stores, and review generated files before reusing them in future sessions or committing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill advertises very broad natural-language triggers such as 'document system', 'generate references', and 'maintain docs', which can match many ordinary user requests and cause the skill to activate unintentionally. Because this skill appears designed to inspect code/systems and generate persistent reference documentation, accidental invocation could expose internal architecture, configurations, file indexes, or other sensitive operational details beyond the user's immediate intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal