Agent OKR

Security checks across malware telemetry and agentic risk

Overview

The available signals show a coherent planning/reporting skill with a disclosed file-writing concern that users should review, but no evidence of malicious behavior.

Before installing, expect the skill to create or update local OKR/report YAML files and review diffs before committing them. Use it in a repository where those files are appropriate, and avoid treating generated planning data as authoritative without human review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly describes an automated workflow that writes weekly report data into repository-tracked YAML files, but it does not clearly warn that using the skill will modify files in the repo. In an agent setting, silent or poorly disclosed file mutation can cause unintended commits, overwrite human edits, or create integrity issues in operational planning data, especially if triggered automatically on a schedule.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal