Narrative Focus

Security checks across malware telemetry and agentic risk

Overview

The skill appears to perform purpose-aligned post-processing edits, with no evidence of hidden access, exfiltration, destructive behavior, or unsafe persistence.

Install only if you are comfortable with the skill proposing or applying edits to drafts. Prefer using it in review/diff mode first, and ask it to confirm before overwriting important files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README states that in post-processing mode the agent will 'identify misalignments, fix them' without an explicit safeguard requiring user confirmation before modifying drafts or files. In agent environments that can edit workspace content, this can normalize autonomous content changes and lead to unintended or silent modifications, especially when the user only asked for review or analysis.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal