Back to skill

Security audit

Ink — React for interactive command-line apps.

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only guide for building Ink/React terminal apps, with no hidden execution or data access found.

Install this if you want Ink or React-based terminal UI guidance. For plain shell scripts, non-React CLI tools, or simple colored console output, the skill may be broader than needed, but no security-relevant hidden behavior was found.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger section is broad enough that the skill may activate for many generic terminal, dashboard, prompt, or colored-output requests, even when the user did not specifically ask for Ink. In an agent environment, overly broad activation can cause inappropriate skill selection, lower-quality guidance, or unintended steering toward this stack, though it does not directly create code-execution or data-exfiltration risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.