Back to skill

Security audit

teamarchitect-skill

Security checks across malware telemetry and agentic risk

Overview

This skill appears purpose-aligned and not malicious, but it can change the local agent setup by installing or creating other skills with limited review controls.

Install only if you are comfortable with a skill that can guide broad changes to your local agent setup. Before approving any install or creation step, review each recommended skill individually, prefer trusted and pinned sources, check requested permissions and changed files, and keep an uninstall or rollback path.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README states that core skills are installed automatically and optional skills may also be installed, but it does not clearly warn users that invoking the skill can change their local environment or install additional components. In a skill that recommends and assists with installation, this increases the risk of users consenting to broader system changes than they realize, which could enable unwanted package installation or trust-chain abuse if recommendations are compromised.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.