Back to skill

Security audit

Verificate Cn

Security checks across malware telemetry and agentic risk

Overview

This skill coherently adds a hosted code-and-plan validation service, with the main risk being that user code or plans may be sent to an external MCP endpoint for review.

Install this only for projects where it is acceptable to send code, documentation, plans, or AI outputs to Verificate's hosted MCP service. Review the provider's privacy and pricing terms, and be aware that the recommended always-on instruction can let the verifier block or shape when the agent considers work complete.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.