Back to skill

Security audit

Irenk_FNG

Security checks across malware telemetry and agentic risk

Overview

This identity skill is purpose-aligned, but it handles persistent agent identity keys and linking actions with unsafe or under-scoped instructions.

Install only if you are prepared to review or supply the missing scripts yourself. Do not paste real private keys, JWTs, or reusable identity tokens into commands or chat. Treat human-agent linking as a persistent identity action: confirm the DID, challenge, requester, registry destination, and agent name before running it, and configure encryption or a secret store before creating real identities.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:132