Back to skill

Security audit

Ai Code Review Expert

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only code review skill with no executable installer, persistence, hidden data handling, or artifact-backed malicious behavior.

Reasonable to install if you want an AI code-review prompt. Be aware it may activate on broad code-review phrases, and you should avoid sharing proprietary or sensitive code unless you are comfortable with the agent context receiving it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list contains broad, common phrases such as 'check this code' and 'review this PR' that can cause the skill to activate in contexts where the user did not explicitly intend to invoke it. In an agent environment, this increases the chance of unintended routing, accidental exposure of sensitive code to the skill, or interference with other skills handling adjacent tasks.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.