Work Receipt

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward coding-session summary helper, but its generated receipts may include private project or terminal details.

Install only if you are comfortable with the agent inspecting your current coding-session context. Review and redact generated receipts before sharing them in standups, tickets, PRs, or chat, especially for tokens, credentials, customer data, sensitive paths, command output, and unfinished security-sensitive work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly analyzes sensitive local artifacts including git history, diffs, tests, and terminal commands, but it does not clearly warn users before doing so. This can lead to unintentional exposure of secrets, internal project details, command history, or proprietary work product in the generated receipt or any downstream sharing of that receipt.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal