Back to skill

Security audit

Agent BOM Compliance

Security checks across malware telemetry and agentic risk

Overview

The skill is a local compliance/SBOM documentation skill with no executable payload, no hidden install behavior, and only a minor documentation ambiguity about optional network use.

Before installing, treat scans as local by default and only enable any remote enrichment or template fetching after confirming what endpoint is used and what project data, if any, is sent. Protect generated reports because they may contain project inventory or compliance details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The README presents two conflicting security claims: one section says optional network access may be used for SBOM enrichment or report templates, while the embedded reference states all scans run locally and no sensitive information is transmitted. This can mislead users into enabling or trusting behavior under false privacy assumptions, increasing the risk of unintended data exposure during compliance analysis.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.