Operator

Security checks across malware telemetry and agentic risk

Overview

The skill is a code-review helper, but it runs nested review tooling with full filesystem and command access by default, so users should review that authority before installing.

Install only if you are comfortable with a review helper that can run a nested reviewer in full-access mode by default. Prefer using --no-yolo or AUTOREVIEW_YOLO=0 unless you intentionally want that broader authority, and review any output file path or parallel test command before running it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill advertises destructive and highly sensitive capabilities such as deleting instances, managing secrets, writing workspace files, and changing automations, but it does not require confirmation prompts or present clear user-facing warnings. In practice, this increases the risk of accidental destructive actions or unsafe delegation of high-privilege operations through natural-language requests.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal