Back to skill

Security audit

SSH Essentials (Security Remediation)

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only SSH command reference with visible, user-run examples and no hidden execution or installation behavior.

Install this only if you want an SSH command reference. Review commands before running them, especially rsync --delete, StrictHostKeyChecking=no, agent forwarding, background tunnels, and SSH server configuration changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The document explicitly states that the approval thresholds are not met, then immediately assigns an approval-style verdict anyway. In a QA or release-gating workflow, this contradiction can cause reviewers or automation to treat an unapproved plan as cleared, weakening security and quality controls.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The contradictory status language creates an unsafe process condition: readers are told the plan failed the stated approval thresholds, yet are also told it is 'APPROVED_WITH_WARNINGS' and 'production-ready for implementation.' That ambiguity can be exploited socially or operationally to bypass intended review gates and move changes forward without satisfying policy.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.