Back to skill

Security audit

se-semantic-graph

Security checks across malware telemetry and agentic risk

Overview

This skill stores user-confirmed project knowledge in a local graph to guide software work, with no evidence of hidden exfiltration or destructive behavior.

Install only if you want an opinionated, local semantic-graph workflow for projects. Expect it to ask for staged confirmation of personas, requirements, and architecture before coding, and verify the lobster-memory/axolotl dependency setup because the skill relies on those local components.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger phrases include broad everyday expressions such as '修 bug 前查上下文', '这段代码为什么存在', and '为何这么设计', which can match normal software-development conversation and cause unintended activation. Accidental invocation can steer user workflows, inject unnecessary procedural constraints, or expose project-context tooling in conversations where the user did not intend to use this skill.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.