Security audit
Code Tester
Security checks across malware telemetry and agentic risk
Overview
The skill mostly matches its build/test purpose, but an included path-resolution helper unsafely uses shell eval on user input, which could let a crafted project path run commands.
Review before installing. The advertised build/test behavior is understandable, but build tools and tests can run arbitrary project code, and the included path resolver should be fixed to remove unsafe `eval` before accepting untrusted directory names. Prefer running this skill in a sandbox and only against trusted project directories.
SkillSpector
By NVIDIA
SkillSpector findings are pending for this release.
VirusTotal
64/64 vendors flagged this skill as clean.
