Back to skill

Security audit

Compliance Scan Report

Security checks across malware telemetry and agentic risk

Overview

This is a coherent compliance-scanning skill, but users should scope scans carefully because reports may include sensitive code or secrets.

Install only if you are comfortable letting the agent inspect the code or snippets you provide. For production repositories, narrow the scan path, avoid including unnecessary regulated datasets, and ask the agent to redact secret values and sensitive personal data in its report.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger conditions are broad enough to activate on generic mentions of compliance, audit, security, or privacy review requests, which can cause the skill to run outside the user's specific intent. In practice this may lead to unintended repository scanning or processing of sensitive code and data context when the user only asked a general question, increasing data exposure and misapplication risk.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill encourages scanning repositories and data-processing flows for secrets, personal data, and regulated information, but it does not warn users that the scan itself may surface, copy, or further process highly sensitive content. Without an explicit warning and handling guidance, users may inadvertently expose credentials, PHI, PCI data, or personal data to the agent workflow or logs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.