Back to skill

Security audit

Nmap Recon

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Nmap guidance skill for authorized network scanning, with the main risk being misuse against targets the user is not allowed to test.

Install only if you intend to perform authorized network security checks. Treat every scan as an active network action: specify the exact target, confirm you own it or have written permission, avoid unapproved production or public infrastructure, and be careful with sudo, aggressive timing, vulnerability scripts, and exploit/auth NSE categories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description contains broad trigger phrases such as 'recon' and 'nmap' that could cause the skill to be invoked in contexts where the user did not clearly request active network scanning. Because this skill performs potentially sensitive security actions, unintended invocation increases the risk of unauthorized scanning, policy violations, or accidental use against the wrong target.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.