Security audit
缺陷报告
Security checks across malware telemetry and agentic risk
Overview
This skill provides QA bug-report templates and guidance, with sensitive-data cautions and no hidden persistence or data transfer behavior found.
Safe to install for QA documentation workflows. Before using it with real bugs, avoid pasting production secrets, customer records, financial credentials, identity numbers, phone numbers, or unredacted screenshots/logs, and only run any optional packet-capture or log commands in an environment you control.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
