Skill

Security checks across malware telemetry and agentic risk

Overview

The skill has a coherent evaluation purpose, but its installer can automatically delete the configured install directory during a failed update, so it needs review before use.

Review the install script before running it. Do not set EVOLUTION_INSTALL_DIR to a broad or important directory, and consider installing from a reviewed, pinned commit or release. Use a dedicated LLM API key and run tests against copies or sandboxed agent files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
If `git pull --ff-only` fails, the installer unconditionally deletes the existing installation directory and reclones it. This can destroy local changes, uncommitted work, or user-maintained files in that directory without warning or confirmation, creating a reliability and potential data-loss issue.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal