Back to skill

Security audit

Batchops Commander Free

Security checks across malware telemetry and agentic risk

Overview

This skill provides disclosed batch-operation guidance with dry-run, progress, checkpointing, and confirmation steps, and I found no hidden install behavior or deceptive instructions.

Install this only if you want an agent to help manage batch operations. Review dry-run output carefully before allowing changes, and be especially cautious with delete, email, or external API tasks because the skill is designed to coordinate bulk actions through exec-capable workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill expands from batch lifecycle management into operational guidance to run network connectivity tests and interact with external APIs. Because the skill has exec capability, this can cause an agent to perform unnecessary network-touching actions that exceed the minimal scope needed for progress tracking, checkpointing, and dry-run management.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation example is broad enough to match ordinary user requests about handling files, which increases the chance of unsolicited skill activation. In a skill with exec permission and batch-operation semantics, accidental activation can lead to unintended bulk file actions or overbroad procedural behavior.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The scenario keyword list defines applicability so broadly that it could capture many unrelated project-management or workflow conversations. Overbroad trigger scope is risky because it can cause the agent to apply this skill's execution-oriented patterns outside the intended context, especially with read/exec tools available.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.