Back to skill

Security audit

Phy Content Compound

Security checks across malware telemetry and agentic risk

Overview

This skill is a local content-indexing helper that does what it says, but users should point it only at folders they are comfortable having summarized or printed.

Install only if you want a local tool to scan your writing archive. Run it on a dedicated content folder, not your home directory or folders containing private journals, client notes, credentials, or unpublished material you do not want echoed in terminal or JSON output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill is designed to recursively scan a user's past content and extract reusable text fragments with source attribution, yet it provides no privacy notice, data-handling explanation, or warning about accidental ingestion of sensitive material. In context, this is risky because creator content folders may contain drafts, client notes, unpublished material, or personal information that could be indexed and surfaced later.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
This tool scans a user-specified directory, reads all matching .md/.txt files, extracts content snippets, and can print both extracted text and source metadata directly to stdout or JSON. In a skill context, that creates a real privacy and data-exposure risk because users may point it at folders containing sensitive notes, drafts, credentials, personal journals, or proprietary content without clear consent prompts, filtering, or redaction.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.