Back to skill

Security audit

资源交付分发

Security checks across malware telemetry and agentic risk

Overview

The skill appears to perform its stated distribution function, but external uploads/publication may happen without a clear preview or confirmation step.

Install only if you are comfortable with the agent publishing or uploading content to the configured platforms. Before using distribution, verify the destination accounts, content package, and platform list, and prefer manual confirmation or a dry-run workflow if available.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The distribute command triggers uploads immediately without any confirmation, dry-run preview, or explicit acknowledgment of target platforms. In a workflow handling external distribution, this increases the risk of accidental publication of materials to third-party platforms, which can cause data leakage, compliance issues, or reputational harm.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal