Back to skill

Security audit

Jungle Executor

Security checks across malware telemetry and agentic risk

Overview

The available evidence shows a possible over-broad trigger description, but no concrete malicious behavior, hidden install step, persistence, or unsafe data handling.

Before installing, review the skill description and make sure you want it to activate in the contexts it names. If it might affect high-stakes decisions, constrain when your agent may use it or keep it disabled unless explicitly requested.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The description and usage conditions are broad enough to trigger this skill across trading, high-stakes decisions, and general workflow enforcement, which creates ambiguous activation boundaries. In an agent system, this can cause the skill to be invoked outside its intended context and let its rigid instructions override safer task-specific policies or decision logic.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.