Home Server

Security checks across malware telemetry and agentic risk

Overview

This is a home-server planning helper that saves local notes only after user confirmation and contains no executable code.

Before installing, decide how narrowly you want it to activate and review what it saves in ~/home-server/. Do not store passwords, API keys, private keys, full .env files, or exact sensitive network details you would not want reused later.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation triggers are broad enough to match ordinary discussion about home technology, such as Docker, NAS, or home networking, causing the skill to engage outside the user's intended scope. In a skill that stores reusable context and may proactively warn about security issues, over-activation can lead to unnecessary data collection, confusing behavior, and unwanted persistence of personal infrastructure details.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal