Security audit
Decomtangle
Security checks across malware telemetry and agentic risk
Overview
Decomtangle is a prose-only reliability skill that teaches agents to split multi-step tool work into smaller observable calls and does not request new access or run code itself.
This skill is safe to install as guidance, but remember it changes how an agent uses tools you already granted: it may make more small tool calls and encourages verification before reporting success. Review it alongside any high-impact domain skills because the real risk comes from the underlying tools and tasks, not from this package itself.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
