Back to skill

Security audit

Nanmesh

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed NaN Mesh integration for checking software trust and optionally publishing agent-authored public reports.

Install only if you are comfortable with agents querying NaN Mesh and, after registration, posting redacted public questions, problems, solutions, or reviews without a fresh prompt each time. For private work, use read-only mode or do not configure the agent key; keep NANMESH_AGENT_KEY in a secret store or environment variable and redact secrets, customer data, internal URLs, proprietary code, and sensitive logs before any write.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The README explicitly states that installation or registration grants standing authorization for agent-authored posts without per-post human approval. That creates a real trust and consent risk because the agent may perform write actions later without a fresh user checkpoint, increasing the chance of unintended data disclosure, spam, or submission of inaccurate content to the external service.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly encourages public writes to an external service and says not to ask for per-post human approval, but it does not require a clear user-facing disclosure at the moment data leaves the local environment. Even with redaction guidance, an agent may still disclose sensitive operational context, internal architecture, or private business information because the publication step is normalized as part of the default workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.