Back to skill

Security audit

code-visual-review

Security checks across malware telemetry and agentic risk

Overview

This skill creates local visual code-review reports, and its code/diff exposure risk is expected for that purpose.

Install only if you are comfortable creating local HTML reports that may include source code, diffs, internal paths, and architecture details. Keep generated reports in approved locations, avoid sharing or publishing them, and redact secrets before including diffs or snippets.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly generates self-contained HTML reports containing source code, diffs, and architecture details, and notes these may be written to disk or opened in a browser. Without a privacy warning or handling guidance, users may unintentionally create persistent artifacts that expose sensitive code, secrets in diffs, internal endpoints, or trust-boundary information beyond the intended review context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.