Back to skill

Security audit

CMIC Skill Scanner (Linux x64)

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local security-scanning wrapper with optional upload, LLM, and external-engine features that users must configure explicitly, though its reporting features can expose sensitive scan details.

Use the native engine if you want to avoid invoking any locally configured external scanner. Only enable --upload-url or --use-llm with endpoints you trust, because scan findings, summaries, and native LLM text packets may reveal private package details even when source-code upload is not intended.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The installation guide instructs users to upload scan results to a remote URL and explicitly notes that the payload includes full scan summaries and findings, but it does not present a strong warning about the sensitivity of that data or require explicit acknowledgment. Scan reports may contain proprietary skill contents, security findings, file paths, or other sensitive metadata, so silent or under-emphasized transmission to external infrastructure creates a meaningful data exfiltration and privacy risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.