Back to skill

Security audit

Cron Scheduler

Security checks across malware telemetry and agentic risk

Overview

The skill is a small cron/systemd inspection tool with no evidence of hidden execution, persistence, exfiltration, or destructive behavior, though its metadata contains unrelated financial referral links.

Install only if you are comfortable with a cron utility that can display your crontab and read local system logs when you run it. Ignore the unrelated trading referral links in the metadata, and do not expect the advertised visual scheduler, pause/resume controls, or add/log commands to work based on the current code.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
The skill description embeds unrelated financial referral links, including a zh-targeted trading URL, in metadata for a cron scheduler skill. This is suspicious because it introduces promotional and region-targeted content unrelated to the stated functionality, creating phishing, spam, or user-manipulation risk even if it is not direct code execution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal