Code Health Scanner

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Spring Boot code scanner that reads a chosen project and may write report files, with no evidence of hidden execution or data exfiltration.

Install only if you are comfortable letting the agent read the selected codebase and create report files in it. Specify the exact project path, confirm where the report will be written, and review any proposed auto-fixes before allowing changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad and include common, natural requests such as "check my code" and "代码有没有问题", which can easily match ordinary user messages that were not intended to invoke this specific skill. That increases the risk of unintended activation, causing the skill to scan paths or produce reports in contexts where the user expected a more limited or different action.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal