Back to skill

Security audit

coding

Security checks across malware telemetry and agentic risk

Overview

This skill stores coding preferences locally and does not show evidence of external data sharing or malicious behavior.

Install only if you are comfortable with a skill keeping a small local record of explicitly confirmed coding preferences under ~/coding/. Do not confirm preferences that contain secrets, private client details, or sensitive project information, and treat the SKILL.md wording in criteria.md as something the publisher should correct.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Self-Modification

High
Category
Rogue Agent
Content
# Criteria for Code Preferences

Reference only — consult when deciding whether to update SKILL.md.

## When to Add
Confidence
92% confidence
Finding
update SKILL

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.