Back to skill

Security audit

Receiving Code Review

Security checks across malware telemetry and agentic risk

Overview

This skill is a code-review workflow guide with some malformed routing metadata, but no hidden destructive, credential-stealing, or exfiltration behavior was found.

Install only if you want an agent to be more deliberate when handling code-review feedback. Be aware that the metadata should be cleaned up because it may trigger less precisely than intended, but the reviewed artifact does not show malicious behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger engine states the skill activates whenever the user requests something that 'matches the description above,' but the description is malformed and broad. This can cause unintended invocation in adjacent contexts, leading the agent to apply this skill's behavioral constraints when they were not explicitly requested.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The frontmatter description is corrupted with graph syntax and vague invocation language, which makes matching behavior unpredictable and overly permissive. An agent may activate this skill on loosely related prompts, causing instruction bleed and incorrect workflow selection.

Natural-Language Policy Violations

High
Confidence
88% confidence
Finding
The frontmatter description is written in Indonesian without any indication that language selection depends on user preference. In systems that use metadata for routing or prompt construction, this can force a locale mismatch, degrade comprehension, and cause accidental invocation or incorrect behavior for users expecting another language.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.