Back to skill

Security audit

ponytail-audit

Security checks across malware telemetry and agentic risk

Overview

This skill is a read-only repo-wide simplification audit, with no evidence of hidden execution, persistence, data exfiltration, or code mutation.

Install only when you want an agent to inspect the full repository for simplification opportunities. It should not edit files, but a full-repo audit can still place private code into the agent's working context.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill defines a very broad activation phrase, 'ponytail-review, repo-wide', without clear constraints on who can invoke it, in what contexts it should run, or what confirmation is required before scanning the entire repository. Broad triggers increase the chance of unintended activation, which can cause the agent to perform expansive analysis on sensitive codebases or consume excessive context/tokens when the user did not explicitly request that scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.