Back to skill

Security audit

breadcrumb-generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a focused breadcrumb navigation guide, with only a limited note that it may read named project context files to understand site structure.

Before installing, be aware that the skill may use `.claude/project-context.md` or `.cursor/project-context.md` to infer your site hierarchy. Do not place secrets or untrusted instructions in those files, and tell the agent to skip them if you want breadcrumb advice based only on the prompt.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
88% confidence
Finding
The skill instructs the agent to read local project context files automatically before producing output, without requiring explicit user consent or disclosing that local files may be accessed. In agent environments with filesystem access, this can lead to unintended exposure of sensitive internal project information or over-collection of context beyond what the user expected.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.