Taku Review

Security checks across malware telemetry and agentic risk

Overview

This is a transparent code-review skill that inspects repository diffs and may make small local fixes, with no evidence of hidden behavior, persistence, exfiltration, or destructive actions.

Install this if you want an agentic code-review gate for repositories. Keep work under version control, inspect any edits it makes, and ask for report-only review if you do not want auto-fixes. Be aware that broad review-like prompts may invoke it, so use it in coding contexts where local git and verification commands are acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill advertises very broad trigger phrases such as 'check my diff', '检查一下', and 'before shipping', which can match routine conversational requests and cause the review skill to run in contexts the user did not explicitly intend. Because the skill has Bash, Edit, and Write permissions, over-triggering increases the chance of unnecessary repository inspection or modification and can interfere with safer task routing.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal