Skylv Code Reviewer

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only code review skill with broad but purpose-aligned triggers and no hidden execution, persistence, or data access.

Install this if you want a Chinese-language code review checklist skill. Be aware it may activate for broad code-review or security-audit prompts, so review the instructions first if you do not read Chinese.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The manifest description uses very broad trigger phrases such as code review, security audit, code quality, and bug detection, which can match a wide range of normal user requests. This increases the chance of unintended activation or over-selection of the skill, causing it to handle requests outside a narrowly scoped context and potentially exposing user code or influencing agent routing inappropriately.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
Most of the skill content is written in Chinese without stating a locale restriction or offering a language choice. This can lead to user misunderstanding of the skill’s behavior, limitations, or review guidance, which is a safety and usability weakness because users may invoke the skill without fully understanding what it does or how to use it correctly.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal