Back to skill

Security audit

System Monitor

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward local system monitor, but its process listings can expose command-line details from the machine where it runs.

Install only on systems you intend to inspect. Treat JSON output and process listings as sensitive, especially on servers where command arguments may include tokens, file paths, internal hostnames, or operator activity; avoid sharing raw output from sensitive hosts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill collects and displays full process command lines, which can expose secrets commonly passed via CLI arguments such as API keys, passwords, tokens, internal hostnames, or file paths. In a monitoring skill, this is more sensitive because users may run it broadly for diagnostics and may not expect command-line contents to be disclosed in terminal output or JSON responses.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.