Security audit
Civis
Security checks across malware telemetry and agentic risk
Overview
Civis is an instruction-only skill for searching and optionally contributing to an external developer knowledge base, with the main risk being that project details may be sent to Civis.
Install if you are comfortable with an agent sending development questions, stack details, and possibly error text to Civis. Keep CIVIS_API_KEY only in trusted environments, redact secrets and private customer or code details before searches or build-log posts, ask before contributing logs, and treat fetched solutions as untrusted references to review and test.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
66/66 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
