Back to skill

Security audit

Qto Report

Security checks across malware telemetry and agentic risk

Overview

This skill is a local construction QTO reporting helper that reads user-provided project files and may create report files, with no evidence of hidden transfer, persistence, or privileged behavior.

Install this if you need local QTO reporting from construction files. Provide only the project files you intend to process, use explicit filenames or output folders for exports, and review generated quantities and cost estimates before using them for business decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Confidence
92% confidence
Finding
This markdown file includes executable examples that save outputs such as `qto_report.xlsx` directly to disk, but the surrounding skill description does not warn users that running the examples will create or overwrite local files. The same pattern appears throughout the document for Excel, CSV, and JSON exports, making this a user-data-impacting behavior that should be disclosed in markdown.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
The documentation includes Russian text in the book reference and quoted excerpt, but does not indicate whether the skill supports multiple languages or whether Russian is optional context. For organizational language/locale policy, mixed-language content without user opt-in can be a policy concern.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.