Back to skill

Security audit

update-skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed workflow for updating one skill repository entry, with explicit approval gates before edits and before commit or push.

Install only if you want an agent-assisted workflow that can modify skill files and, after your approval, commit and push repository changes. Review the Gate 1 proposed edits, Gate 2 diff, and any pond-derived usage findings carefully before approving publication.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Self-Modification

High
Category
Rogue Agent
Content
upstream: "keep-a-changelog@2.0.0"
---

# Update Skill

Run a thorough on-demand refresh of one skill in a skills repository. Two hard human-approval gates ensure no edits or commits happen without explicit confirmation.
Confidence
93% confidence
Finding
Update Skill

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.