Back to skill

Security audit

Verified Task 1.0.8

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed verification checklist for agent workflows, with no hidden execution, data access, persistence, or destructive behavior found.

Install this as a workflow discipline or checklist, not as a standalone security control. For payments, publishing, or other irreversible actions, make the integration point explicit, require human approval for FAIL or INDETERMINATE results, and avoid sending secrets or sensitive content to any optional external verifier.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The README presents the skill as if it enforces a hard execution gate ('proceed only if PASS' and no agent override by default), but this file contains only descriptive documentation and no mechanism that guarantees those controls. In an automation context, operators may rely on these claims and deploy the skill assuming protective enforcement exists, creating a dangerous mismatch between expected and actual security behavior.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.