Back to skill

Security audit

Engineering Document Pre-Review

Security checks across malware telemetry and agentic risk

Overview

This skill locally extracts and reviews engineering document facts, with disclosed local outputs and no evidence of hidden upload or unrelated behavior.

Install only if you are comfortable with reviewed engineering documents being parsed locally and written to a local output directory. Use a controlled output folder, consider --skip-extracted-text for sensitive source material, and avoid sharing generated reports or extracted text without redacting customer, contact, pricing, or project details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The script persists the full extracted document text, structured fields, and generated review report to local disk by default, which can expose sensitive engineering, contact, schedule, and safety data to other local users, backup systems, or later unintended sharing. In this skill context, the documents are likely to contain proprietary project details and personal phone numbers, so silent persistence increases confidentiality risk even though there is no obvious exfiltration.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.