Security audit
Geoskill: GEE Minimal Test
Security checks across malware telemetry and agentic risk
Overview
This skill appears to be a documentation-only helper for querying Google Earth Engine dataset metadata, with no hidden execution, persistence, or data-exfiltration behavior in the artifact.
This looks safe from the inspected artifact, but it is incomplete as packaged: the referenced script and catalog asset are absent. Only provide Google service account credentials if you specifically intend to use Earth Engine authenticated upload functionality and understand what that script will do once present.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
