Back to skill

Security audit

Ifa Codesys Recipe

Security checks across malware telemetry and agentic risk

Overview

This skill is a local file-conversion tool for PLC recipe files and does not show hidden, networked, persistent, or credential-related behavior.

Install this only if you intend to work with iFA/CODESYS recipe files. Run it on copies of recipe directories, choose input and output paths deliberately, and validate generated .txtrecipe files before importing them into PLC or production tooling.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The markdown says the workflow should run when the user mentions phrases like '填充', '填凸轮', or '把ProdData填入', but these triggers are informal and not tightly scoped to a specific command or context. It does not provide exclusion conditions or negative examples, so ordinary discussion about filling or cam data could ambiguously activate the skill.

Hidden Instructions

High
Category
Prompt Injection
Content
---
name: ifa-codesys-recipe
description: "Manage CODESYS PLC recipes via iFA Evolution �� create, modify, deploy recipe configurations"
tags: [domain-specific, plc, cli, file-based, report-generation]
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.