Back to skill

Security audit

Supplychainsentinel

Security checks across malware telemetry and agentic risk

Overview

This skill is openly for supply-chain automation, but it can automatically create or update purchase orders and send sensitive business alerts using live company credentials.

Install only with test or least-privilege credentials first. Disable automatic PO creation until validated, require human approval for all ERP or purchase-order writes, restrict Slack and email recipients, store secrets in a secret manager, and ensure monitoring jobs have clear stop controls and audit logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly describes automatically creating purchase orders and updating ERP state early in the workflow without a prominent upfront warning that it can perform external, data-changing actions. In an agent setting, this can cause unauthorized procurement, financial commitments, or workflow changes if a user invokes the skill expecting analysis only.

Missing User Warnings

Low
Confidence
85% confidence
Finding
The configuration section requests multiple high-value secrets and access to operational systems, including API keys, database credentials, and ERP integration details, but does not pair that with a clear privacy and secret-handling warning. In an agent environment, this increases the risk of credential exposure, over-broad access, and accidental disclosure of sensitive supply-chain and procurement data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.