Container Helper

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a normal Docker/container assistance skill, with no evidence of hidden execution, credential theft, persistence, or destructive behavior.

Install only if you want Docker/container assistance. Review generated Docker commands before running them, especially commands that delete images or volumes, alter running containers, push to registries, or affect production systems.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill declares broad tags, keywords, and triggers around Docker/container tasks without narrowly defining activation conditions or safety boundaries. In an agentic environment, overly broad activation can cause the skill to be invoked for unintended prompts, increasing the chance of inappropriate command generation or privileged operational guidance in sensitive Docker contexts.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal