Duplication Removal Via Extraction

Security checks across malware telemetry and agentic risk

Overview

This is a plain refactoring guidance skill whose code-editing and test-running access matches its stated purpose.

Install this if you want an agent to help refactor duplicated code in a repository. Use version control, review the resulting edits, and run tests in an environment where you would normally run that project’s test suite.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description contains many broad natural-language trigger phrases such as 'extract method', 'duplicate logic', and 'same code in multiple classes' that commonly appear in ordinary developer conversations. In an agentic system, this can cause the skill to auto-activate outside its intended scope, leading to unintended code edits or workflow steering in contexts where the user did not explicitly request this refactoring approach.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal