Vulnerability Scanner
Security checks across malware telemetry and agentic risk
Overview
This is a coherent local vulnerability-scanning skill that reads user-selected project files and optionally runs npm audit, with no evidence of hidden persistence, exfiltration, or destructive behavior.
Install only if you intend to run local security scans. Point it at specific projects, not broad home directories, and treat the output as sensitive because it can mention secret types, paths, and vulnerability details. Be aware that npm audit may use your npm configuration and contact npm services for JavaScript projects.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
66/66 vendors flagged this skill as clean.
