Back to skill

Security audit

cli-developer

Security checks across malware telemetry and agentic risk

Overview

This is a plain-text CLI development helper with no executable code, install hooks, hidden behavior, or automatic access to user data.

Safe to install as a third-party CLI development assistant. Review any CLI code it helps generate around password prompts, telemetry, install scripts, auto-updates, and environment-variable handling, because those features can affect user privacy or system behavior even though this skill itself does not implement them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill activates on a very general condition ('When invoked') and immediately instructs the agent to begin querying context and implementing solutions without any scoped trigger, authorization boundary, or task qualification. In an agent system, overly broad activation increases the chance this skill is selected in inappropriate contexts, causing unintended CLI design or tool-building actions to influence unrelated tasks or consume sensitive context.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.