pikoCNC G-CODE

Security checks across malware telemetry and agentic risk

Overview

This is a reference-only CNC G-code skill with no executable code, but users should treat any generated machine instructions as safety-sensitive.

Install this as a reference, validation, or simulator aid only. Before using any G-code on real CNC equipment, compare it with official PikoCNC documentation, simulate or dry-run it, confirm units, coordinates, tool table, clearances, spindle/coolant behavior, and treat unknown commands as errors unless a trained operator explicitly approves them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill provides implementation-oriented machine-control instructions and executable examples for CNC hardware, but it does not include an explicit safety warning that these commands can move real equipment, actuate spindle/tooling, and damage stock, tools, or injure an operator if used directly. In a skill intended for interpreter development or CNC programming, this omission materially increases the chance of unsafe real-world use because readers may treat the examples as safe defaults.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal