Back to skill

Security audit

Afrexai Soc2 Evidence Collector.Skip

Security checks across malware telemetry and agentic risk

Overview

This SOC2 audit helper is coherent and purpose-aligned, but it can help generate scripts that collect sensitive cloud, GitHub, and identity evidence.

Install only if you intend to use it for SOC2 evidence work. Verify the publisher/slug, inspect any generated scripts, run them manually with least-privilege read-only credentials, and store or share evidence packages only after redacting sensitive IAM, GitHub, HR, security, and business information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This markdown file includes shell-script examples that enumerate IAM users, credential reports, security groups, branch protection settings, deployments, and other audit artifacts, then writes them into local evidence packages. Although one script advises redaction before sharing, the skill description does not clearly warn users before generation that the automation may gather sensitive configuration and identity data and store it on disk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal