Back to skill

Security audit

Risk Assessment

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent risk-assessment prompt with a purpose-aligned API example, but users should avoid sending confidential assessment details to external AI providers unless approved.

Install appears reasonable for generating structured security risk assessments. Before using it, review any documents or context you provide for secrets, regulated data, or confidential security details, especially if using the included Anthropic API example or any hosted model workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The function sends arbitrary caller-supplied context directly to the Anthropic API, which can expose sensitive operational, security, or regulated data to a third-party service without any warning, consent flow, classification check, or redaction step in this example. In the context of a risk-assessment skill, users are especially likely to submit confidential security posture details, making accidental disclosure more likely and more sensitive than generic text processing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.