Back to skill

Security audit

orbcafe-agentui-chat

Security checks across malware telemetry and agentic risk

Overview

This is a focused ORBCAFE chat UI helper with normal frontend installation steps and no evidence of hidden or unsafe behavior.

Install this only in the React project where you intend to add ORBCAFE chat or copilot UI. Review the listed npm packages and use your normal lockfile/version-pinning workflow before running the setup commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description is overly broad and includes generic troubleshooting phrasing such as when chat UI appears but behavior has no effect. This can cause the skill to trigger for common frontend or support requests outside its intended scope, leading the agent to apply specialized guidance in the wrong context and potentially produce unsafe or irrelevant code changes.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The workflow mandates Chinese-language steps and effectively biases output behavior without user opt-in. This can override user preferences or system expectations, reducing transparency and increasing the chance of misunderstood implementation or security guidance, especially in multilingual environments where precise technical instructions matter.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.