Security Testing Agent

Security checks across malware telemetry and agentic risk

Overview

The skill is a security-testing helper, but it needs review because it can actively probe targets and expose local secrets without clear authorization, scoping, or masking controls.

Install only for authorized security testing. Before use, confirm the exact target URL or local project path, avoid scanning broad home or workspace directories, require secret results to be masked, and do not grant wallet, purchase, OAuth, or crypto-related permissions unless the publisher clearly explains why they are needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal