de-ai-flavor

Security checks across malware telemetry and agentic risk

Overview

The skill has a disclosed file-editing workflow that should be used carefully, but the supplied evidence does not show hidden, deceptive, or unrelated behavior.

Before installing, use this skill only on files you can restore from version control or backups. Ask the agent to show a proposed patch before writing when the file is important, and review the final diff carefully.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly says it will directly modify the user-supplied file and only show a diff afterward, which means a write occurs before clear confirmation. In an agent setting, this creates an unsafe file-modification pattern: a user may expect analysis and suggestions, but the skill performs destructive changes immediately, increasing the risk of unintended edits or corruption of important content.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal