Back to skill

Security audit

Javascript Toolkit Free

Security checks across malware telemetry and agentic risk

Overview

This is a coherent JavaScript guidance skill with disclosed command capability for code checking, and no evidence of hidden persistence, credential access, exfiltration, or destructive behavior.

Before installing, note that the skill can use command execution for JavaScript checks. Use it for JavaScript pitfall analysis and code validation, and avoid treating its broad trigger wording as approval for deployment or unrelated automation tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger condition is overly broad: 'use for code generation, programming assistance, debugging, testing, development deployment.' In an agent ecosystem, this can cause the skill to activate for many generic software tasks outside its narrowly described JavaScript pitfall-guidance purpose, increasing the chance of inappropriate tool use or unwanted command execution because the skill allows `exec`.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.