Back to skill

Security audit

ia-document-review

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward document-review workflow that can make limited inline edits to reviewed documents.

Install this if you want an agent to review and lightly polish planning documents. Be aware that it may directly edit minor wording or formatting in the document being reviewed; substantive changes should be presented for approval first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
Present findings, then:

1. **Auto-fix** minor issues (vague language, formatting) without asking
2. **Ask approval** before substantive changes (restructuring, removing sections, changing meaning). Ask via AskUserQuestion (Claude Code; load with ToolSearch `select:AskUserQuestion` if not loaded) or request_user_input (Codex); fall back to numbered options in chat. Render the finding per the contract below in visible text in the same turn *before* the question fires -- on harnesses where the question opens a modal it covers the preceding text, so a question stem that carries no decision content strands the reader.
3. **Update** the document inline
Confidence
94% confidence
Finding
without asking

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.