Back to skill

Security audit

agent-bom discover aws

Security checks across malware telemetry and agentic risk

Overview

This skill is a scoped AWS inventory helper that uses operator-approved read-only credentials and local output, with no hidden persistence or telemetry found.

Before installing, make sure you are comfortable granting the agent access to an AWS read-only profile or short-lived role, because the generated inventory may contain sensitive infrastructure metadata. Use the narrowest AWS account, region, services, and output path that match your audit need.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.