NoPUA
Security checks across malware telemetry and agentic risk
Overview
This is an instruction-only coaching skill that encourages persistence and verification, with no executable code, credential handling, persistence, or hidden install behavior.
Install this if you want the agent to be more persistent and proactive when stuck. In sensitive repositories, production systems, or paid APIs, give explicit limits such as ask before running destructive commands, broad searches, deployments, or long-running work.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
