Back to skill

Security audit

t0cksn1per

Security checks across malware telemetry and agentic risk

Overview

This skill has a clear reservation-automation purpose, but it tells the agent to run an unpinned external CLI that was not included for review.

Install only if you trust the external `t0cksn1per` package. Review the exact command before it runs, prefer a visible local browser for first use, use CDP only with a temporary Chrome profile, and stop any remote or headless polling job when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly instructs the agent to generate and run a command locally or on a remote node, but it does not require an explicit user-facing confirmation or warning before subprocess execution. Because the command is parameterized from gathered inputs and may run on a different host, this increases the risk of unintended command execution, misuse of remote resources, or running automation the user did not clearly authorize.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.