gstack Investigate

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only debugging skill whose instructions match its stated purpose; it mostly stays within expected bounds but has minor omissions about required runtime capabilities and where it writes reports.

This skill is an instruction-only debugging guide and appears to do what it says. Before installing, confirm the agent runtime will (1) have git and any test runners available and (2) be allowed to read the target repository and write to its memory/workspace (the skill tells the agent to save reports to memory/). If you plan to let the agent run tests or modify code, ensure those operations run in a safe environment (not production), and avoid granting it access to credentials or secrets it doesn't need. The SKILL.md advises sanitizing data before external searches — keep that practice. If you need higher assurance, ask the skill author to (a) declare required binaries (git, test tools) and the memory/config paths it will write to, and (b) confirm no network uploads of raw traces or secrets will occur.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal