Agent Metrics

Security checks across malware telemetry and agentic risk

Overview

This is a local metrics tool whose behavior matches its monitoring purpose, though its saved error logs and exports should be treated as sensitive.

Install only if you are comfortable with a local metrics file being created. Do not place secrets, tokens, private prompts, or customer data in labels or error details, and review exported metrics before sharing or committing them. Use a trusted source for psutil, and do not run the referenced PowerShell wrapper unless you separately obtain and review it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The code persists user-supplied error details and captured stack traces to a local JSON file, which can include secrets, file paths, tokens, request contents, or other sensitive diagnostics. In an agent context, these records may aggregate sensitive prompts, tool outputs, and runtime failures over time, increasing the chance of unintended disclosure if the file is read, exported, or committed.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal