Back to skill

Security audit

缺陷报告

Security checks across malware telemetry and agentic risk

Overview

This skill provides QA bug-report templates and guidance, with sensitive-data cautions and no hidden persistence or data transfer behavior found.

Safe to install for QA documentation workflows. Before using it with real bugs, avoid pasting production secrets, customer records, financial credentials, identity numbers, phone numbers, or unredacted screenshots/logs, and only run any optional packet-capture or log commands in an environment you control.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.