Back to skill

Security audit

Skill Vetter

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed security-review checklist for vetting other skills, with command use aligned to inspecting files and GitHub metadata.

Install only if you want an agent-side checklist for reviewing other skills. Expect it to read target skill files and possibly run source-check commands such as GitHub API curl queries; review commands before execution if your agent requires confirmation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The capability coverage section includes many broad, fragmented trigger phrases that can overlap with ordinary conversation. In agent skill systems, overly generic matching can cause the skill to activate unexpectedly, which is risky here because the skill declares the exec tool and may steer the agent into command-oriented review flows unnecessarily.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.