Back to skill

Security audit

AI Dev Runtime

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed coding-runtime connector, but it grants broad file-editing and terminal-execution authority through an external runtime without clear safety boundaries.

Install only if you trust the AiDevRuntime server you will connect to. Run it with least privilege, keep it pointed at a trusted local or controlled endpoint, review edits and terminal commands before execution, and verify how its learning memory and API key handling work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The slash-command description advertises that `/ai-dev-runtime <task>` will run a full development workflow for an arbitrary task, including planning, editing, testing, and fixing. Because the trigger wording is broad and task input is unconstrained, users or upstream agents may invoke powerful file-editing and terminal-capable behavior on vague or unsafe requests, increasing the risk of unintended code changes or command execution.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal