4090ctl

Security checks across malware telemetry and agentic risk

Overview

This is a small SSH server-administration runbook, but it exposes real access details and includes service restart commands without clear safeguards.

Install only if you are authorized to administer this exact 4090 server. Verify the SSH host, user, and key path before use, require explicit confirmation before any restart, and treat logs as potentially sensitive data rather than instructions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill includes a service restart command for a production-like Dify deployment without any warning, confirmation step, or guidance on operational impact. An agent or user following this documentation could unintentionally disrupt availability, terminate in-flight work, or cause avoidable downtime on the remote server.

Missing User Warnings

Low
Confidence
97% confidence
Finding
The document exposes internal SSH access details, including a private IP, username, SSH host alias, and the local path to the identity file. While not the key material itself, this materially lowers the barrier to misuse by revealing privileged access patterns and sensitive infrastructure information that could aid lateral movement or unauthorized access attempts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal