Back to skill

Security audit

Incident Hotfix

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed incident-hotfix workflow that creates local branch and documentation artifacts for code triage without hidden persistence or exfiltration.

Install this if you want a local incident hotfix workflow. Before running it, confirm you are in the intended repository, choose the correct production base branch or commit, and review any generated evidence files before committing or sharing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
86% confidence
Finding
The skill instructs the agent to create a hotfix branch and generate incident documentation in the repository, but it does not explicitly warn that these steps modify the working tree and can create files and branches. In an automated or loosely supervised environment, this can lead to unintended repository changes, clutter, or actions performed in the wrong repo/context, especially during a stressful incident response workflow.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.