code-modification-guard

Security checks across malware telemetry and agentic risk

Overview

The skill has no evidence of malware or hidden behavior; the main issue is that its activation wording appears broader than necessary.

This looks acceptable to install if you understand that it may trigger more often than intended. Review the skill description and consider narrowing its trigger wording if it appears during unrelated coding tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The manifest description includes very broad trigger phrases such as 'help me look' and effectively covers most code modification requests, which can cause the skill to activate in situations outside its intended scope. Over-broad activation increases the chance that restrictive or steering instructions in the skill are injected into unrelated workflows, influencing agent behavior unexpectedly.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal