Value & Environment Validator

Security checks across malware telemetry and agentic risk

Overview

This is a coherent shell-validation reference skill with no bundled executable code, hidden behavior, persistence, or data exfiltration.

Install or use this only if you recognize and trust x-cmd, because the documented prerequisite sources ~/.x-cmd.root/X into the shell. The reviewed skill itself is a command reference and does not add hidden code or persistence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description uses extremely generic trigger terms like 'validate', 'check', and 'verify' without tightly constraining what kinds of requests should invoke this skill. In an agent setting, this can cause over-broad routing, where the skill is selected for unrelated user tasks and influences execution flow or environment decisions in contexts the author did not intend.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal