Security audit
Ponytail Gain
Security checks across malware telemetry and agentic risk
Overview
This is a display-only skill that shows a benchmark scoreboard and does not request file, network, credential, or persistence access.
Installing this should only add a command-like skill that displays a fixed Ponytail benchmark scoreboard. Users should treat the benchmark numbers as general project claims rather than measured results for their own repository, which the skill itself also discloses.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
59/59 vendors flagged this skill as clean.
