Security audit
Encrypted File Writer
Security checks across malware telemetry and agentic risk
Overview
No malicious or suspicious behavior was evidenced in the supplied scan context, but artifact files could not be inspected in this run.
Based on the supplied telemetry, there is no artifact-backed reason to hold this skill for review. Because the package files could not be inspected here, users should still review the skill's stated permissions and install instructions before installing, especially if it requests credentials, broad local file access, or persistent background behavior.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
