Analyze Open Source

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only code-analysis skill that reads a repository and produces a Chinese architecture report, with no evidence of credential use, persistence, file mutation, or data exfiltration.

Install this if you want repository analysis reports in Chinese. Because the skill asks the agent to read project files, use it only on codebases you are comfortable having analyzed, and avoid pointing it at private repositories containing secrets unless that is intentional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill unconditionally requires all analysis output to be in Chinese, overriding user preference and reducing transparency for users or reviewers who do not read zh-CN. In a code-analysis skill, this can hinder oversight, validation, and safe use of the generated report, especially in mixed-language or enterprise environments where English is expected.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal