Back to skill

Security audit

Shadows Doc Forge

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent documentation helper that reads project files and creates markdown docs, with no executable code or hidden behavior found.

Install with normal caution. Use it on repositories you intend to document, review generated markdown before committing or publishing, and explicitly tell the agent whether it may create new files or modify existing source files for inline comments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly states that it will generate and write new documentation files, but it does not require explicit user confirmation before creating files or clearly warn about repository modification side effects. In an agent context, silent file creation can overwrite expectations, pollute a repo, or create unwanted changes that may later be committed, so this is a real safety issue even though the stated purpose is documentation generation.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.