CVE Audit Skill

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward dependency vulnerability audit helper, with normal caution around running an external CLI and approving package updates.

Install this if you want an agent workflow around osv-ui dependency scanning. Review the exact npx command and any proposed package update commands, be cautious if it activates on a generic security request, and run your normal tests after approving dependency changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation phrases are broad enough to trigger on many general security-related requests such as 'security', 'scan', or 'vulnerability', which may cause this skill to activate outside its intended dependency-audit context. Because the skill can invoke package scanning and later suggest or apply dependency changes, accidental activation can lead to confusing behavior, unnecessary command execution, or inappropriate tool use in unrelated conversations.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal