Automation Scripts

Security checks across malware telemetry and agentic risk

Overview

This is a small, transparent automation-scripts skill whose file and scheduling examples match its stated purpose, with no hidden installer or executable payload found.

Install only if you want an agent to help run local automation tasks. Before using it, verify exact source and destination paths, avoid scheduling broad or destructive commands, and review any scraping or screenshot targets for privacy and terms-of-use concerns.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises file renaming, backup, screenshotting, and scheduled command execution without any warnings, confirmation requirements, or scope limitations. In an agent setting, these operations can alter files, persist recurring actions, or capture external content, increasing the risk of unintended destructive changes or privacy-impacting behavior if invoked loosely.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal