Code Review

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only code review guidance skill with no executable code, credential use, persistence, or hidden data flow.

Safe to install as a code review reference. Users should still review generated comments before posting them and avoid sharing private source code with an assistant unless their organization permits it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest trigger phrases include generic terms such as "peer review," "code quality," "review standards," and especially "lint" and "static analysis," which can arise in many adjacent workflows rather than specifically invoking this skill. The description does not provide exclusion conditions or boundaries clarifying when the skill should not activate, increasing the risk of over-broad matching.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal