Security audit
code-score
Security checks across malware telemetry and agentic risk
Overview
This is presented as a Go code-scoring skill, but its Markdown instruction files are unreadable binary data, so users cannot verify what it actually tells an agent to do.
Do not treat this as confirmed malware, but install only after the publisher provides readable plain-text SKILL.md, README.md, and config.md that match the Go code-scoring description. The current package shows no visible credential use, persistence, or executable behavior, but its instructions are not reviewable.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
