Back to skill

Security audit

Html Coder Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward HTML coding helper with some overly broad activation wording but no hidden, persistent, destructive, or data-exfiltrating behavior.

Install this only if you want an HTML-focused coding assistant. Review or narrow its trigger wording if your environment auto-invokes skills, and approve any suggested command such as npx validation or ping only when it matches your current task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger conditions are broad enough to match generic software-development requests such as code generation, debugging, testing, and deployment. In an agent ecosystem, this can cause the skill to activate outside its intended HTML-only scope, increasing the chance of inappropriate tool use, misleading output, or interaction with unrelated tasks where the skill's assumptions are unsafe.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The capability coverage keywords are excessively broad and ambiguous, including generic terms like development tools, core capabilities, and standard compliance checks. Such loose matching can lead to accidental invocation on unrelated development tasks, which expands the skill's effective authority and can route agent behavior through instructions not intended for the user's actual context.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.