Back to skill

Security audit

Agent Routing Waste Audit

Security checks across malware telemetry and agentic risk

Overview

This is a read-only audit skill for spotting agent routing and cron cost waste, with no executable code or hidden mutation behavior found.

Install is reasonable if you want read-only routing and cron waste review. Because the skill may inspect logs, prompt previews, and run summaries, redact secrets or private payloads before pasting them and review any recommendations manually before changing production jobs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The example job name mixes English with Chinese text ("14天SEO报告"), which reflects a locale-specific language choice in natural-language content. The file does not explain that multilingual content is optional, user-selected, or limited to a region-specific context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.