Back to skill

Security audit

Phy Platform Rules Engine

Security checks across malware telemetry and agentic risk

Overview

This is a local social-media draft checker that reads user-provided text and prints rule-based feedback, with no evidence of credential use, network transfer, persistence, or account changes.

Install only if you are comfortable running a local Python checker on drafts you choose. Avoid feeding it secrets, personal data, or embargoed material unless you are authorized to analyze that content, and treat the platform-ranking advice as advisory rather than guaranteed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
87% confidence
Finding
The skill encourages users to analyze draft social-media posts, which may contain unpublished marketing plans, embargoed announcements, customer details, or other sensitive text, but it does not warn users about that risk. In context, this increases the chance of accidental exposure or mishandling of sensitive content because users are prompted to pipe drafts and files directly into the tool without privacy guidance.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.