Ra Pro

Security checks across malware telemetry and agentic risk

Overview

Ra Pro is a disclosed research-report skill that installs a display library, uses a user-provided topic and license key, and saves a local Markdown report without evidence of hidden or malicious behavior.

Use this in a virtual environment or otherwise understand the impact of the pip install command. Set OUTPUT_FILE only to a filename or trusted path, check for existing files before running, and avoid using sensitive research topics unless you are comfortable saving the generated report locally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill instructs the agent to write a file automatically without an explicit user-facing warning or confirmation at execution time. In agentic environments, silent file creation can surprise users, overwrite existing files, or persist sensitive research content to disk in unintended locations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal