Code Reviewer

Security checks across malware telemetry and agentic risk

Overview

This is a coherent local code review helper that reads user-selected code, runs local analysis scripts, and optionally writes a local HTML report.

Install only if you want a local code review assistant. Scope reviews to the files or directories you intend to inspect, and keep generated reports private because findings may include source snippets or exposed secrets from the reviewed project.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
75% confidence
Finding
The trigger phrases include broad natural-language requests such as '检查安全问题' and '找出代码中的 Bug', which can match many ordinary conversations and unintentionally invoke a high-capability skill. Because this skill may read files and execute local scripts, accidental activation increases the chance of unnecessary code access or command execution in sensitive environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal