Back to skill

Security audit

Software Delivery Team — Agent Configuration Bundle

Security checks across malware telemetry and agentic risk

Overview

This is a coherent software delivery team skill that discloses code editing and command execution roles, with no hidden installer, exfiltration, or destructive behavior found.

Install this only if you want an agentic software delivery workflow that can modify files, run local commands, use web lookups, and store work context. Review changes before release or publication, and avoid using it in repositories where broad command execution or persistent memory would be inappropriate.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill grants multiple roles both file-write and shell-execution capabilities, which can modify the local system, repository state, or execute arbitrary commands, yet the skill description does not clearly warn users that it can make persistent system changes. This creates a safety and consent problem: users may invoke the skill expecting analysis or coordination, while the agent is actually empowered to alter files and run commands across the workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.