database-optimizer

Security checks across malware telemetry and agentic risk

Overview

This is a database performance tuning skill with real operational risk if used on live systems, but its behavior is disclosed, purpose-aligned, and instruction-only.

Install only if you want an assistant for database performance work. Start with read-only diagnostics, require explicit approval before index, schema, configuration, replication, or caching changes, test in staging when possible, and keep backups or rollback plans for production systems.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly says it will "implement comprehensive performance improvements" and later describes an "Implementation Phase" that applies query, index, configuration, and schema changes, but it does not require explicit user confirmation before making potentially disruptive database modifications. In a database-optimization context, these actions can degrade performance, lock tables, alter schemas, or affect availability if applied automatically or against production systems.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal