Back to skill

Security audit

Java Reviewer Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill is a Java code review helper, but it grants shell execution while its activation and operation wording are broader than its stated purpose.

Install only if you are comfortable with a Java review skill that can read files and run shell commands. Use it on explicit Java diffs or source files, and require confirmation before it runs builds, Git commands, file writes, imports, exports, or any deployment-related command.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger condition is overly broad, covering generic coding, debugging, testing, and deployment scenarios rather than narrowly constraining activation to Java code review. In an agent ecosystem, this can cause the skill to activate on unrelated requests and gain access to read/exec pathways in contexts where the user did not specifically ask for code review, increasing the chance of unintended command execution or over-collection of workspace data.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The capability scope enumerates many broad keywords and operational verbs without clear guardrails, making the skill appear applicable to a wide set of requests beyond its stated purpose. In context, this is more dangerous because the skill declares allowed-tools: read exec, so vague activation can expand an exec-capable skill into sessions that should remain informational or read-only.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.