Back to skill

Security audit

Python Exec

Security checks across malware telemetry and agentic risk

Overview

This skill is framed as Office document creation, but it exposes a broad local Python execution command that can affect the filesystem beyond that purpose.

Review this carefully before installing. It may be useful if you intentionally want an agent to run local Python for document generation, but it is not narrowly limited to Office files; only activate it in a workspace where arbitrary local Python execution and file writes are acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.