Cli Developer

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only CLI development guide, and the sensitive-looking examples are aligned with normal CLI-building guidance rather than hidden behavior.

This appears safe to install as a CLI-development reference. Review generated CLI code before running it, especially examples involving credentials, config files, plugin loading, deployment commands, force flags, or sudo guidance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger list includes several broad, common terms such as "CLI," "command-line," and names of popular frameworks, which can cause the skill to activate in contexts where it was not specifically intended. This can lead to inappropriate routing, overbroad application of the skill, and reduced reliability of agent behavior, though it does not by itself enable direct code execution or data exfiltration.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal