Back to skill

Security audit

Paper Reading Problem Reality Check

Security checks across malware telemetry and agentic risk

Overview

This skill is a structured research-review workflow that reads local research notes and writes clearly scoped markdown review files.

Before using it, confirm which workspace root the agent will use. Expect it to read linked local research artifacts and create or update markdown files under research-question-checks for the selected card.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly instructs the agent to create and update multiple files in a local workspace, but it does not require obtaining user confirmation before performing those writes. In an agent setting, this can lead to unexpected filesystem modifications, accidental overwrites, or persistence of generated artifacts the user did not intend to create, especially when workspace-root may be inferred from user-provided paths.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal