Back to skill

Security audit

JSON YAML Converter

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation helper that reads and edits repository docs, including agent instruction files, and its broader behavior is mostly disclosed and purpose-aligned.

Install only if you want an agent to help audit and edit repository documentation, including agent/contributor instruction files. For sensitive repos, use report-only mode or review proposed changes carefully before allowing edits to AGENTS.md, CONTRIBUTING.md, .agents, .cursor, or similar workflow-control files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill description is overly broad and does not define clear invocation triggers, boundaries, or permitted operations. In an agent ecosystem, vague scope can cause the skill to be invoked in unintended contexts, increasing the chance of misuse, inappropriate tool access, or user confusion about what actions the skill will perform.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.