Back to skill

Security audit

Collaborate

Security checks across malware telemetry and agentic risk

Overview

This skill provides disclosed collaboration and decision-recording guidance, with a manageable privacy consideration around its default local decision log.

Before installing, decide whether local decision logging is appropriate for your work. For confidential projects, set log_decisions to false, use your team's existing ADR or record convention, or avoid recording sensitive objections verbatim.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill specifies persistent logging of collaboration decisions to a user-home file and includes fields that can capture sensitive context such as objections, owners, and decision rationale, but it provides no warning, consent gate, or minimization guidance. In this collaboration context, the risk is elevated because routine planning/review discussions often include internal strategy, personnel details, or confidential project information that may be retained longer than users expect.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.