misra-automotive-c

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only MISRA C review skill with broad activation terms but no hidden execution, credential access, persistence, or destructive behavior.

Install this if you want MISRA C review assistance for automotive embedded C. Be aware it may activate on broad automotive safety terms, and treat ASIL classifications and replacement code as draft guidance that must be checked with certified MISRA tooling and qualified reviewers before safety-critical use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list is broad and includes generic phrases such as "review my c code," "embedded c review," and "asil," which can cause the skill to activate in contexts that are not specifically requesting MISRA analysis. Unintended activation can lead to prompt hijacking of normal C-review workflows, incorrect tool selection, or unnecessary exposure of user code to a specialized review path.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation guidance defines when to activate but not when to avoid activation, so the skill may be invoked for general C programming, ISO 26262 discussion, or embedded debugging requests that do not need MISRA auditing. In an agent environment, ambiguous scope increases the chance of misrouting user intent and over-applying rigid review behavior where it is not appropriate.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal