Find Skills 0.1.0

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill does what it says, but users should review any third-party skill before allowing a global no-confirm install.

Before installing a skill this finds, review the exact package name, source page, publisher, and repository. Prefer seeing the command first, and avoid global no-confirm installation unless you trust the selected skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill recommends `npx skills add <owner/repo@skill> -g -y`, which combines global installation with confirmation suppression and no accompanying warning about trust, scope, or review of third-party packages. In a skill-discovery workflow, this increases the chance that an agent or user installs unvetted remote code with system-wide effect and reduced friction for accidental or unsafe execution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal