Skylv Secrets Scanner

Security checks across malware telemetry and agentic risk

Overview

This is a simple local secret-scanning guide with no executable code, persistence, or data-sending behavior.

Install this only if you want an agent to inspect selected project files for possible leaked credentials. Run it on intended repositories rather than broad home or system directories, and avoid sharing raw scan output because it may contain real secrets that should be rotated.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill defines a very broad trigger phrase ('secrets-scanner') relative to its security-sensitive functionality, and the description also advertises generic terms like 'security scan' and 'check api key'. Broad or underspecified activation can cause the skill to run in unintended contexts, potentially scanning repositories or exposing sensitive matches when the user did not clearly request that action.

Vague Triggers

Low
Confidence
85% confidence
Finding
The usage guidance includes ambiguous activation criteria like 'security audit', which is broader than secret scanning and could cause the skill to activate when a user intended a different type of review. In a security-oriented skill, ambiguous invocation increases the chance of overreach, unnecessary repository inspection, or disclosure of matched secret-like strings in normal workflows.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal