Back to skill

Security audit

Flowchart

Security checks across malware telemetry and agentic risk

Overview

This is a coherent CellCog diagram-generation skill with expected external processing and shareable outputs, and no hidden or destructive behavior in the inspected artifact.

Before installing, treat anything you include in prompts, uploaded files, or generated diagrams as content processed by CellCog and potentially exposed through shareable URLs. Avoid secrets, credentials, regulated data, and sensitive internal architecture unless your organization has approved that use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly encourages users to describe systems and processes in plain English and states that CellCog produces shareable interactive URLs, but it does not warn that those prompts and system descriptions are sent to an external service. This creates a meaningful risk of unintended disclosure of sensitive architecture, business process, or organizational information, especially because users may assume the skill operates locally or only returns a private artifact.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.