ReAct Loop

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only problem-solving workflow skill; it is broad but coherent and does not install code, request secrets, or add persistence.

Install only in environments where the agent’s available tools are appropriately scoped. Require explicit confirmation before database writes, migrations, deployments, external messages, issue creation, or other irreversible actions, especially if the agent has production access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly presents impactful actions such as executing SQL, deploying to staging, sending email, posting to Slack, and creating GitHub issues as normal ReAct steps without requiring user confirmation, safety checks, or scope restrictions. In an agent setting, this can normalize autonomous side-effecting behavior and lead to unauthorized changes, communications, or operational disruption if the model follows the examples literally.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal