Back to skill

Security audit

NEXUS Code Review

Security checks across malware telemetry and agentic risk

Overview

This paid remote code-review skill is mostly disclosed, but it needs Review because it can automatically send source code and payment authorization to a third-party service without clear approval limits.

Install only if you trust NEXUS to receive reviewed code and to process the configured payment proof. Use sandbox_test or a tightly scoped payment proof where possible, redact secrets and proprietary code, and configure your agent to ask before each remote paid request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The README states the skill is 'automatically invoked' when a matching task is detected, but it does not define the matching criteria, required user consent, data scope, or trust boundaries. In an agent ecosystem, ambiguous auto-invocation can cause unintended routing of sensitive code or prompts to a remote third-party service, increasing the risk of data exfiltration and surprise billable actions.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill's invocation guidance is very broad ('use when you need a security and quality review of code') and lacks clear limits on what code, data classes, or trust levels are appropriate to send to the external service. In this context, that can cause agents to transmit sensitive source code, secrets, proprietary logic, or regulated data to a third-party endpoint without an explicit gating step, user confirmation, or data-classification check.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.