Back to skill

Security audit

Acpx Harness Routing

Security checks across malware telemetry and agentic risk

Overview

This skill is not malicious, but it routes delegated agents with blanket approval and persistent sessions, which can allow unattended file-changing work.

Install only if you are comfortable with delegated Claude/Codex/Gemini harness runs proceeding without case-by-case approval. Use it in a disposable or tightly scoped workspace, set explicit task boundaries, and avoid using it where agents could touch sensitive files, credentials, production systems, or important repositories without review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill is written entirely in Chinese and presents mandatory operational rules without offering any mechanism to respect the user's preferred language. In practice, this can cause operators or downstream agents to misunderstand approval, execution, or safety-critical routing instructions, increasing the chance of incorrect tool use or unsafe actions.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly states that Claude/Codex can write files and frames harnesses as execution workers, but it does not require a user confirmation or warning before modifying workspace contents. Combined with the instruction to use approve-all and non-interactive execution, this increases the risk of silent or unintended file changes in the user's environment.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.