test-skill22131

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed 1Password CLI helper; it handles sensitive vault access, but its behavior is purpose-aligned and includes appropriate guardrails.

Install this only if you want an agent to help operate 1Password CLI. Authorize only the intended 1Password account, specify the exact vault or item before any secret access, avoid commands that print secret values, prefer op run or op inject, and confirm the tmux session is closed after use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal