code-polish

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a disclosed code-review helper, with broad repository access that fits its review workflow but should be used deliberately.

Install this only if you want an agent to help review repository changes. Treat it as a powerful development helper: confirm when it should run, review any suggested fixes before applying them, and be aware that review tooling may inspect local code and run project commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger set includes broad everyday phrases such as 'simplify', 'review changes', and 'review code', which can cause the skill to activate in contexts where the user did not intend a powerful review-and-fix workflow. Because the skill can run project commands, inspect diffs, launch sub-agents, and later modify code after approval, accidental invocation increases the chance of unintended code access, noisy automation, or risky repository actions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal