Back to skill

Security audit

Code

Security checks across malware telemetry and agentic risk

Overview

This is a general coding assistant skill that discloses read and command execution capability, with no hidden scripts, persistence, credential theft, or destructive behavior found.

Install only if you want a broad coding workflow skill with command execution available. Review commands before running them, keep work scoped to the intended repository, and do not place real secrets in the generic API_KEY example unless the agent environment truly needs them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill advertises itself for broadly defined coding, debugging, testing, and deployment tasks across multiple agent platforms without clear activation boundaries or safety gating. In practice, this can cause the skill to be invoked for a very wide range of common requests and, because it exposes an exec-capable workflow, increase the chance of unnecessary command execution or over-privileged behavior in contexts where a narrower skill should have been selected.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.