Back to skill

Security audit

Coding Contract

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only skill for generating and saving coding specification documents, with no evidence of hidden execution, credential use, network access, or destructive behavior.

Install this if you want an agent to generate reusable coding contract/spec files. Before using it, confirm the feature scope and output path, and ask the agent to check whether the target file already exists before saving.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger condition is broad enough to activate on generic brainstorming or design-document content, which can cause the skill to run in contexts where the user did not explicitly request spec generation. That increases the chance of inappropriate auto-activation, unnecessary file creation, or the model steering the session into a workspace-writing flow without clear user intent.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill directs the agent to save a generated file to the workspace by default, but it does not require an explicit user-facing warning or confirmation before modifying files. In an agent setting, silent writes can surprise users, overwrite expected locations, or create persistence from loosely inferred intent, especially when combined with broad triggering behavior.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.