Back to skill

Security audit

Code Quality Paid

Security checks across malware telemetry and agentic risk

Overview

This skill is a code security audit helper that uses expected local scanning commands and report files, with no evidence of hidden data theft, persistence, or destructive behavior.

Install this only where you are comfortable allowing the agent to read and scan the target repository and create local audit reports. For large or sensitive projects, specify the target directory and output directory explicitly before running a full audit.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill includes a broad natural-language invocation to perform a comprehensive code security audit, which in this skill context can trigger large-scale scanning and report generation across the current project. Because the skill has exec capability and examples that write artifacts, an underspecified trigger increases the risk of unintended workspace-wide actions, excessive resource usage, or execution on sensitive repositories without explicit scoping confirmation.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill documents report generation and output to files such as JSON, SARIF, and HTML without clearly warning the user that it will write artifacts into the workspace. In an agent environment with execution support, silent file creation can overwrite existing files, leak scan results into shared directories, or create unintended artifacts in CI/CD contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.