Back to skill

Security audit

Agentsec

Security checks across malware telemetry and agentic risk

Overview

This appears to be a purpose-aligned security scanning skill, with the main caution that its default scan may read broader local skill or project folders than some users expect.

Before installing or running it, review what folders `agentsec` will scan and prefer an explicit path when you only want one project checked. Treat generated reports as potentially containing local file paths, skill metadata, or snippets from private local skill files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly recommends running `npx agentsec` as the default action, and the documented behavior is to scan default skill directories across the machine plus nearby project folders. Even with read-only permissions, this broad auto-discovery can expose unrelated local repository names, file paths, manifests, and potentially sensitive skill content without first prompting the user to narrow scope or acknowledge the scan breadth.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.