Back to skill

Security audit

verbs-to-urma-converter

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent RDMA-to-URMA migration helper, but users should review its broad activation and insecure token-exchange guidance before installing.

Install only if you intentionally want verbs/libibverbs code migrated to URMA. Before using generated networking or remote-memory code in production, require authenticated encrypted peer exchange, avoid fixed or plaintext tokens, validate peer identity, and review all output under urma_output/ before building or running it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description activates on broad RDMA-related terms such as 'ibv_*', 'rdma', and 'InfiniBand', which can match users seeking explanation, debugging, or design help rather than migration. In an agent environment, over-broad activation can cause the wrong skill to seize control and produce large-scale code transformation guidance or file operations that the user did not intend.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The enumerated trigger phrases are ambiguous because they include generic protocol and library names without requiring a conversion request. This increases the chance of accidental invocation on unrelated RDMA tasks, leading to mis-scoped actions, unnecessary code changes, or misleading migration instructions in contexts where no URMA transition is desired.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.