tsx

Security checks across malware telemetry and agentic risk

Overview

This skill is a small, disclosed component-tooling helper whose bundled executable only prints messages and shows no hidden data access, persistence, network use, or destructive behavior.

This appears safe to install as a lightweight or placeholder skill, but users should understand that it does not actually scaffold components yet. Because it requests exec permission, review the shell script before allowing autonomous agent use, especially if a future version changes the script to write project files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal