Back to skill

Security audit

Privacy Check

Security checks across malware telemetry and agentic risk

Overview

This is a coherent local privacy scanner, with caveats around protecting generated reports and using context or HTML output carefully.

Use it only on files or folders you intend to scan. Keep generated reports private because even masked findings can reveal sensitive structure, and prefer the default no-context mode unless surrounding lines are necessary. Avoid HTML reports for untrusted scan inputs or filenames unless you are comfortable with local report-rendering risk.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The printed summary says '如需关闭请上传时不带 --context 参数' inside a branch that only executes when context is already present, contradicting the actual CLI semantics and likely intended guidance. In a privacy-scanning tool, misleading operators about whether contextual data is included can cause accidental retention, sharing, or publication of extra surrounding sensitive content, increasing sensitive-data aggregation risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.