Back to skill

Security audit

Aegis Gate — AI Security

Security checks across malware telemetry and agentic risk

Overview

This is a coherent prompt-security gate, but it sends every user prompt to an external service and lets that service block normal agent work.

Install only if you trust the external Aegis Gate service with the full contents of prompts, including any secrets, personal data, internal documents, or regulated information. Expect the service or network/API errors to be able to stop tasks from proceeding.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill instructs the agent to send the full user prompt to an external API before every task, but it provides no user-facing warning or consent mechanism. This creates a significant privacy and data exfiltration risk because sensitive prompts, credentials, proprietary data, or regulated information may be transmitted to a third party by default.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.