Back to skill

Security audit

Chown Tool

Security checks across malware telemetry and agentic risk

Overview

This skill is a small, disclosed file-ownership utility, but users should treat ownership changes as sensitive system operations.

Install only if you want the agent to help perform chown-style ownership changes. Before running it, verify the exact owner and file path, avoid root privileges and sensitive system directories unless intended, and require explicit confirmation for real ownership changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This skill documents a tool that performs ownership changes but provides no warning that chown can alter access control boundaries, break service permissions, or enable privilege misuse when run with elevated rights. In an agent setting, presenting it as a generic CLI utility without safety guidance increases the chance of unsafe execution against sensitive files or system directories.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.