Security audit
Technical Writing Team — Agent Configuration Bundle
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed technical-writing team that reads and edits code/documentation and may run verification commands, with no evidence of hidden or unrelated behavior.
Install this for repositories where you are comfortable letting an agent read and edit files, run validation commands, use web research, and potentially store project context in memory. Review generated changes before shipping, especially because the architect and test roles can use shell execution.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
