Game Changing Features

Security checks across malware telemetry and agentic risk

Overview

This is a product-strategy skill that may inspect a project and save local notes, but those behaviors are disclosed and fit its purpose.

Install only from a source you trust. Use this skill in the intended project workspace, expect it to inspect project context for product evidence, and review generated .claude/docs/ai notes before committing or sharing them because they may include internal product observations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs the agent to write output into the workspace without an accompanying warning, confirmation step, or constraint on when file modification is appropriate. In practice, this can lead to unintended filesystem changes, pollution of repositories, or overwriting/creating artifacts during ordinary advisory use when the user may have expected a chat-only response.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal