Back to skill

Security audit

Tmp Domain Kit

Security checks across malware telemetry and agentic risk

Overview

The skill is a local domain-knowledge toolkit that reads user-chosen files into a local knowledge store, with no evidence of hidden network transfer or destructive behavior.

Install only if you want a local searchable knowledge base for engineering/domain files. Treat extracted content as persistent local knowledge: review files before ingesting them, especially spreadsheets or code that may contain secrets, personal data, or proprietary details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Ssd 3

Medium
Confidence
88% confidence
Finding
The generic summarization path copies raw cell contents from user-supplied tables into output entities, including up to several rows and columns verbatim. If the extractor processes sensitive spreadsheets, this can unintentionally propagate secrets, personal data, or operational details into downstream knowledge stores, logs, or model prompts beyond the minimum necessary for parsing.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.