Code & Design Review

Security checks across malware telemetry and agentic risk

Overview

The skill is internally consistent with its stated purpose: it provides local review prompts and simple shell scripts for post‑coding code and UX reviews, and it does not request extra credentials, installs, or network access.

This skill appears coherent and low-risk: the scripts simply format and print code/diffs into review templates and the prompts guide human/AI reviewers. Before installing, consider: (1) Do you want post‑coding reviews to run automatically or only when you invoke them? The README encourages adding mandatory agent instructions — doing so will make reviews run more broadly. (2) The review prompts ask you to paste code or pipe diffs; if your agent sends that data to a remote model (cloud API), sensitive source code may be transmitted off‑site. If your code is sensitive, restrict reviews to local models or run the scripts manually. (3) Inspect and run the two included scripts locally to confirm they behave as expected (they only read files/stdin and print templates). If you accept the integration recommendations, update your agent instruction files deliberately (and back them up) rather than blindly applying them.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal