Code Generation

Security checks across malware telemetry and agentic risk

Overview

This is a simple instruction-only coding helper with no executable code, installer, credentials, network behavior, or persistence.

This appears safe to install as a generic coding assistant. Because it is broad, use it only when you want code help, review generated code before running it, and avoid pasting secrets or private credentials into prompts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill is triggered by very broad, everyday requests such as '补全这个函数的实现' and '重构这段代码更简洁' without any explicit routing boundaries, exclusions, or confirmation requirements. In an agent environment, this can cause over-invocation or incorrect invocation on unrelated coding conversations, increasing the chance that the skill handles sensitive code or user intent when it should not.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal