Back to skill

Security audit

Loop creator

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed guide for building supervised self-running agent loops with state, gates, cost checks, and command guardrails.

Install this only if you want help designing unattended automation. Before enabling any generated loop, verify the trigger, command allowlist, hard-stop gate, state file, maximum iterations, and whether it can push commits, open PRs, comment, label, or make other account-visible changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Ssd 1

Medium
Confidence
94% confidence
Finding
This section instructs the model to ignore externally injected 'MANDATORY' directives based on its own relevance judgment. That creates a semantic instruction-priority override, which is dangerous because an attacker can frame legitimate higher-priority policy or orchestration directives as 'false-positive injections,' causing the agent to bypass controls or required workflows.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.