Back to skill

Security audit

Code Tester

Security checks across malware telemetry and agentic risk

Overview

The skill mostly matches its build/test purpose, but an included path-resolution helper unsafely uses shell eval on user input, which could let a crafted project path run commands.

Review before installing. The advertised build/test behavior is understandable, but build tools and tests can run arbitrary project code, and the included path resolver should be fixed to remove unsafe `eval` before accepting untrusted directory names. Prefer running this skill in a sandbox and only against trusted project directories.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal