Security audit
thinking-scientific-method
Security checks across malware telemetry and agentic risk
Overview
This skill is a narrow debugging-thinking guide that asks the agent to compare hypotheses and run cheap checks, with no hidden execution, data access, persistence, or privilege requests.
Installers should expect this skill to shape how an agent reasons during ambiguous debugging tasks. It does not add executable code or special access, but the agent may still inspect relevant project files or logs when a debugging task calls for it.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
