Back to plugin

Security audit

AI Engineering Expert

Security checks across malware telemetry and agentic risk

Overview

This plugin provides disclosed, bounded AI coding and project-governance workflows with project-local write limits and explicit stop conditions.

Install only if you want an agent that can proactively edit and test files inside your project. Review the active packet/write scope before using autonomous loops, and do not grant production credentials, account sessions, paid resources, or destructive Git operations unless you explicitly intend to handle those decisions outside the skill's normal bounds.

SkillSpector

By NVIDIA

SkillSpector was not run because this plugin release contains no bundled skills.

VirusTotal

62/62 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
skills/agent-loop-engineering/scripts/test-state-tools.mjs:82
Evidence
const execution = spawnSync(process.execPath, [script, "--workspace", root, "--json", ...extra], {