Miroprism

Security checks across malware telemetry and agentic risk

Overview

MiroPRISM is a coherent review workflow skill, with disclosed local outputs and subagent use that users should understand before running it on sensitive material.

Safe to install for normal use. Before running it on proprietary code, secrets, regulated data, or private security findings, redact sensitive values and remember that review material may be shown to multiple subagents and stored locally under analysis/miroprism; keep that directory out of public commits or backups if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The README instructs users to review output under `analysis/miroprism/archive/...` and later documents persistent run artifacts including reviewer outputs, digest logs, and hashes, but it does not clearly warn that submitted artifacts and generated analysis will be written to disk. For a review skill likely to process sensitive code, design docs, or security findings, undisclosed local persistence increases the risk of accidental data retention, exposure to other local users/processes, and inclusion in backups or source-control commits.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal