Back to skill

Security audit

rotifer-agent

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Rotifer CLI workflow guide, and its command, file, and network access fit its agent-building purpose.

Before installing, understand that this skill can guide your assistant to run Rotifer CLI commands, install the CLI from npm if needed, query the public Rotifer registry, and create or modify project-local Gene and agent files. Review proposed install, publish, or overwrite commands before approving them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
This manifest describes the skill in very broad terms such as building AI agents from intent and running in seven steps, but it does not specify concrete trigger phrases, scope boundaries, or exclusion conditions. In a manifest file, this kind of open-ended activation description can cause unintended invocation overlap with other general agent-building or automation requests.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The manifest requests process execution, filesystem write access, and outbound network access, which can affect system integrity and user data, but the description does not disclose these impactful behaviors. For a skill description, users should be warned when the skill may execute commands, modify files, or send data over the network.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.