Security audit
skill-factory
Security checks across malware telemetry and agentic risk
Overview
This skill is a transparent workflow for helping agents create and review other skills, with no hidden execution code or unrelated sensitive behavior found.
Review generated skills before publishing or installing them, especially if this factory creates scripts, network integrations, or credential-dependent workflows. The factory itself is disclosed and low risk, but its outputs can vary by user request.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
