Back to skill

Security audit

Topos

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed code-quality helper that runs an external Topos tool, with no hidden artifact behavior found.

Install only if you trust the Topos publisher and are comfortable running its installer and optional MCP server. Use it as a structural code-quality aid, not as your sole security review or correctness check.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The skill says to load Topos when the user asks to improve code quality, reduce complexity, check structural security footguns, verify a refactor, or optimize toward medals. These triggers are broad and overlap with many normal development tasks, which can cause an agent to invoke the skill in situations where its installation and execution steps are unnecessary or where its partial security framing ('SECURE') may be over-trusted. In this context, the danger is not direct code execution from the text itself, but over-activation and misplaced reliance on a tool that explicitly does not provide full SAST coverage.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.