Web Coder

Security checks across malware telemetry and agentic risk

Overview

This is a broad web-development reference skill with no executable code, install hooks, credential access, or hidden behavior found.

Install this as a general web-development knowledge aid. Review any commands or code it helps generate before running them, especially deployment, package installation, authentication, or security-related changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill’s activation criteria are extremely broad, covering nearly any HTML, CSS, JavaScript, HTTP, security, performance, or web-related discussion. Overly broad routing can cause the agent to invoke this skill in many contexts where narrower or safer handling would be preferable, increasing the chance that expansive instructions or referenced materials influence unrelated tasks.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal