Back to skill

Security audit

PIPL Check

Security checks across malware telemetry and agentic risk

Overview

This is a local PIPL self-assessment/report generator with disclosed file output and no evidence of hidden data access, network use, or persistence.

Install only if you are comfortable running a local compliance helper that writes report files in your working directory. For stricter environments, pin and review the optional reportlab dependency before enabling PDF output, and treat the generated compliance content as a self-check aid rather than legal advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Unpinned Dependencies

Low
Category
Supply Chain
Content
# pipl-check 依赖
# 基础功能无需额外依赖(Python标准库即可)
# reportlab(可选,用于PDF报告生成)
reportlab>=4.0
Confidence
91% confidence
Finding
reportlab>=4.0

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.