Nmap

Security checks across malware telemetry and agentic risk

Overview

This appears to be an Nmap-focused skill whose main risk is that network-scan guidance must only be used on authorized targets.

Install only if you want Nmap-related assistance, and require explicit confirmation before any live scan. Use it only against systems you own or are authorized to test, and do not grant sudo or broad network access automatically.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The 'When to Use' section is broad enough that the skill could be invoked for many generic nmap-related requests without sufficient scoping. In an agent environment, vague triggers can cause over-selection of this skill, increasing the chance that shell-backed commands are run unnecessarily or in the wrong context.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal