Back to skill

Security audit

Agent Code No.7 Commander

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only coordinator skill for business, legal, finance, research, and due-diligence tasks, with no executable code or hidden access requests.

Safe to install based on the provided artifacts. Users should still avoid sharing unnecessary sensitive documents and should verify legal, tax, financial, audit, or due-diligence conclusions with qualified professionals before acting on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill advertises that users can invoke it with arbitrary natural-language requests and that the commander will automatically analyze and route work, but it does not define clear domain, safety, or authority boundaries. In an agent setting, this can cause overbroad activation, misrouting of sensitive tasks, or unauthorized handling of requests outside the intended legal/finance/research scope, increasing the chance of unsafe delegation and data exposure.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.