Back to skill

Security audit

CoralOS

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill clearly describes a user-directed Coral Cloud workflow for launching and managing remote agent sessions, with no hidden local code or deceptive behavior found.

Install this only if you intend to operate Coral Cloud remote-agent sessions. Before creating a session, review the selected agent, payload, namespace, and expected permissions or costs, and treat any separately downloaded helper scripts or templates as unreviewed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the user to create and launch a remote-agent session but does not warn that this action can trigger execution by external agents with real side effects, network activity, tool use, or cost. In a skill specifically designed to discover and run remote agents, omission of consent and risk guidance materially increases the chance of unsafe or unintended execution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.