Back to skill

Security audit

CMIC Skill Scanner (Linux ARM64)

Security checks across malware telemetry and agentic risk

Overview

This skill is a security scanner wrapper that keeps scanning local by default and only sends data when configured, though its docs reference a bundled binary that was not present in the inspected artifact.

Use --engine native if you do not want the wrapper to call an external scanner. Only use --upload-url or --use-llm with endpoints you trust, because reports and LLM packets can reveal security findings or selected package text. Verify or build the scanner binary before running it, especially because the inspected artifact did not include the referenced binary or checksum file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The installation guide documents an upload feature that sends embedded review details, including full scan summaries and findings, to a remote URL, but it does not clearly warn users that potentially sensitive package analysis data will leave the local environment. In enterprise use, scan findings can contain proprietary code metadata, internal paths, or sensitive security observations, so understated disclosure increases the risk of unintended data exfiltration to third-party infrastructure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.