Back to skill

Security audit

orbcafe-stdreport-workflow

Security checks across malware telemetry and agentic risk

Overview

This is a coherent ORBCAFE UI development skill with disclosed setup commands, examples, and no hidden execution or data collection behavior.

Install this only in the intended ORBCAFE UI project, review npm dependency changes before running setup, choose the locale your app needs, and ensure generated quick create/edit/delete callbacks enforce your normal authorization, confirmation, and audit behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The workflow steps are written as mandatory instructions in Chinese, while the rest of the document mixes English and Chinese. This creates a natural-language policy concern because the skill appears to require a specific language/locale without offering user opt-in or documenting a justified region-specific constraint.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown file contains a code example that explicitly sets `locale="en"`, which forces a specific language/locale. The file does not indicate any user opt-in, configurability, or region-specific justification, so it appears to violate the natural-language policy against unprompted locale enforcement.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.