TIA HW AUDITOR

Security checks across malware telemetry and agentic risk

Overview

The skill has a legitimate industrial audit purpose, but it gives an agent broad network-file access and external script execution without enough scoping or provenance control.

Review before installing. Use only a vetted audit script from a fixed trusted location, restrict the agent to read-only allowlisted backup paths, and ensure heartbeat automation can only be triggered by trusted operators or systems.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill explicitly allows accessing network paths for a NAS/engineering vault and executing an external batch script, but it does not define any approval, path restrictions, provenance checks, or disclosure requirements. In an agent setting, this can lead to unauthorized access to sensitive backups, execution of untrusted code, or unintended data exposure through generated CSV/JSON outputs.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal