Security audit
qapten-codex
Security checks across malware telemetry and agentic risk
Overview
This is an instruction-only deployment guide whose sensitive commands and credentials match its stated developer workflow, with clear cautions included.
Install only if you want a Codex/GitHub/deployment checklist. Treat the commands as powerful: avoid `--sandbox danger-full-access` except in an isolated container or VM, use least-privilege and preferably short-lived tokens, never commit real `.env` files or private keys, and review deployment commands before running them against production.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
VirusTotal findings are pending for this skill version.
Static analysis
No suspicious patterns detected.
