Back to skill

Security audit

Afrexai Cybersecurity Engine Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed cybersecurity assessment guide that uses read and command execution capabilities in ways that match its stated purpose, with no evidence of hidden persistence, exfiltration, or destructive automation.

Install only if you are comfortable giving the agent read and command-execution capability for security assessment tasks. Run scans or remediation commands only against systems you own or are authorized to test, and review commands that can change dependencies, infrastructure, or production services before approving them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly declares the `exec` tool and presents active security assessment and hardening workflows, but it does not clearly warn users that commands may execute on the local machine or interact with real infrastructure targets. In a security-oriented skill, users may reasonably follow suggested actions such as scans, audits, or remediation commands, which can alter systems, hit production assets, or expose sensitive data if run without explicit consent and safety boundaries.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.