Security audit
Python Exec
Security checks across malware telemetry and agentic risk
Overview
This skill is framed as Office document creation, but it exposes a broad local Python execution command that can affect the filesystem beyond that purpose.
Review this carefully before installing. It may be useful if you intentionally want an agent to run local Python for document generation, but it is not narrowly limited to Office files; only activate it in a workspace where arbitrary local Python execution and file writes are acceptable.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
VirusTotal findings are pending for this skill version.
Static analysis
No suspicious patterns detected.
