Back to skill

Security audit

Toml Validator

Security checks across malware telemetry and agentic risk

Overview

This is a focused TOML validation helper that only reads user-specified TOML files and shows validation, structure, or diff output.

Install if you need TOML validation or inspection. Use it on specific .toml files you intend to examine, and avoid the show or diff commands on configs containing tokens, passwords, or private endpoints unless you are comfortable with those values appearing in the agent conversation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The manifest description includes the trigger phrase "config file validation," which is broader than the TOML-specific scope of the skill and overlaps with common requests about many configuration formats. Because the trigger list does not clearly constrain this phrase to TOML-only contexts or provide exclusions, the skill could be invoked for unrelated config-validation tasks.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.