Back to skill

Security audit

Api Scaffold Gen Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward API scaffold generator; its command and file-writing capabilities match that purpose, with normal caution needed before running generated install or server commands.

Install only if you want an agent to generate and possibly write API scaffold files. Before approving any generated exec command, check package installs, server startup, network tests, and file writes, especially in an existing project.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill advertises and enables exec-based workflows but does not clearly warn that generated or suggested commands can modify the local system, install packages, or trigger network activity. In an agent setting, this increases the chance that users approve unsafe command execution without understanding filesystem, package-installation, or environment side effects.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.