knitting-pattern

Security checks across malware telemetry and agentic risk

Overview

This is a simple knitting-pattern helper with no bundled executable code, but users should confirm the missing script and API provider before using it.

Install only if you intended to use a knitting-pattern lookup helper. Before setting KNITTING_API_KEY, confirm what service it belongs to, what searches will be sent externally, and where the referenced knitting_pattern.py script comes from.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill's usage triggers are broad and underspecified, including phrases like 'crafts related functionality' and 'Diy operations', which can cause the agent to invoke this skill outside a narrowly appropriate context. While not directly exploitable as code execution, overbroad routing increases the chance of unintended external calls or misuse of associated resources.

Missing User Warnings

Medium
Confidence
81% confidence
Finding
The skill requires an API key but does not disclose what external service is contacted, how credentials are handled, or any constraints on transmission and logging. This creates risk of accidental credential exposure, unexpected data egress to third parties, and unsafe operational use in environments that assume local-only behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal