Back to skill

Security audit

Skill Update

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed update-management workflow that changes installed skills only after preview, backup, and explicit approval.

Install this if you want an agent to manage skill updates for you. Expect it to inspect skill diffs, create backups, write an update log and config, and retain brief metadata about hand-edited skill customizations; review previews carefully before approving updates, especially update-all, migrations, or changes to agent behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
83% confidence
Finding
The skill instructs persisting a per-skill local edit history to a file in the user's home directory, but it does not explicitly tell the user that customization metadata will be stored or obtain consent for that retention. Even if the data seems low sensitivity, edit names, file paths, section names, and one-line intents can reveal workflow details, preferences, or internal project context, creating a privacy and data minimization issue.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.