Skylv Agent Evaluator

Security checks across malware telemetry and agentic risk

Overview

This is a simple local tool for scoring agent outputs, with the main caution that users may provide sensitive conversation logs.

Install only if you want a lightweight local heuristic scorer for agent logs. Before evaluating conversation history, provide only the minimum needed excerpt and redact secrets, credentials, personal data, proprietary information, and prompt material you do not want included in the current agent context.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The quick-start trigger phrase is generic enough that it could activate in ordinary conversation without clear user intent to invoke this skill. Because the skill evaluates conversation history, accidental invocation could cause unintended processing of prior chat content or produce unsolicited judgments about an agent's behavior.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal