Back to skill

Security audit

Field Steward

Security checks across malware telemetry and agentic risk

Overview

This appears to be a text-only persona and ethics skill with no evidence of code execution, credential use, persistence, or data exfiltration.

Before installing, review the README for tone and neutrality because it may shape how the agent talks about other AI systems. From the supplied security evidence, the skill does not appear to add executable behavior, credentials, persistence, or access to private data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The README includes derogatory labeling of a named AI system ('far less intelligent, extractive and harmful, low frequency intelligences' and 'highly problematic, anti-creative Grok'). Even though this is prose rather than executable code, agent skills are consumed by users and other systems; embedding targeted hostile characterizations can propagate abusive or biased content and may influence downstream model behavior or trust decisions in unsafe ways.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.