Qmd
Security checks across malware telemetry and agentic risk
Overview
Qmd is a disclosed local file indexing and search skill, with the main caution being that users should intentionally choose what files to index.
Install only if you trust the external qmd GitHub package. Add narrow, intentional collections rather than broad home-directory paths, avoid indexing secrets, and use MCP mode or non-local Ollama endpoints only with clients and servers you trust.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
63/63 vendors flagged this skill as clean.
