Security audit
Demo Skill 3
Security checks across malware telemetry and agentic risk
Overview
This skill only provides structured feedback on a product idea and explicitly tells the agent not to use network access, private files, or shell commands.
This appears safe to install for product-idea feedback. If the idea is stored in a file, only point the agent at the specific file you intend it to read; the skill itself says not to read private files or use the network or shell.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
