Codebase Index — 代码库索引系统
Security checks across malware telemetry and agentic risk
Overview
This skill is a local codebase indexing tool that reads a user-specified project and writes a searchable JSON index without network activity or hidden persistence.
Install only if you want a local code indexer. Run it on intended project directories and treat the output JSON as potentially sensitive, because it may include file paths, docstrings, imports, symbol names, and limited variable value representations from your code.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
