Paper Viz

Security checks across malware telemetry and agentic risk

Overview

The only supported concern is ordinary local file creation, which appears purpose-aligned but should be used with attention to where files are written.

Before installing or using it, choose an explicit output directory, avoid running it in sensitive folders, and check whether it can overwrite existing files. If you do not want persistent generated files, ask the agent to preview the planned paths first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to create directories and write multiple files to local disk automatically, including choosing fallback writable directories, without requiring explicit user confirmation at the time of modification. In an agent setting, this can cause unintended filesystem changes, overwrite risks, or data leakage into unexpected locations, especially because the workflow is execution-first and minimizes user interruption.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal