Security audit
Docxtpl
Security checks across malware telemetry and agentic risk
Overview
The skill is mostly a normal DOCX templating helper, but its batch renderer can write generated files outside the chosen output folder when CSV values contain path-like text.
Install only if you trust the CSV data or are comfortable reviewing/fixing the batch filename handling. Avoid path-like id values, do not use --overwrite with untrusted data, and run the batch script in a contained working directory until filenames are sanitized.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
66/66 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
