Back to skill

Security audit

verification-gate

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only verification workflow skill; its testing and staging guidance is purpose-aligned, but users should scope staging tests carefully.

Install only if you want a strict code-verification checklist. Before following the staging-service examples, use dedicated staging data, least-privilege test credentials, non-destructive requests where possible, cleanup steps, and explicit approval for any write operation against shared systems.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The guidance explicitly recommends running real requests against staging with real databases, networks, and credentials, but it does not warn about mutation risk, privacy exposure, rate limits, or accidental impact on shared environments. In a verification skill, users are likely to follow these instructions routinely, which increases the chance of unintended data changes or leakage during testing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.