Back to skill

Security audit

Nexus Edge Deployer

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed infrastructure-deployment skill, but users should understand it can guide billable VPS provisioning.

Install only if you are comfortable using an agent to plan or perform cloud infrastructure deployment. Before any live Hetzner action, confirm the target account, API token scope, region, server size, monthly cost, exposed services, and rollback/deletion plan.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly includes automatic Hetzner VPS provisioning via API, but the description and workflow do not prominently warn users that invoking the skill may create billable cloud resources and perform infrastructure changes. In an agent ecosystem, that omission is security-relevant because users may authorize execution without understanding the financial and operational impact, increasing the risk of unintended server creation, exposed services, or configuration drift.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.