Back to skill

Security audit

rotifer-guide

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Rotifer developer helper that routes users through CLI-based onboarding, scaffolding, diagnostics, search, and upgrades without hidden execution or unrelated data access.

Install this only if you intend to work with Rotifer. Review prompts before running npm installs, MCP setup, publish, Arena submit, or Web Studio generation, because those actions can install packages, create project files, contact Rotifer services, or make generated Gene source public.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill is presented as a broad entry point that bundles multiple capabilities such as onboarding, scaffolding, diagnostics, registry search, and upgrade workflows, while the metadata only loosely constrains when it should be invoked. Because the skill also requests powerful permissions including process execution, filesystem write, and outbound network access, over-broad activation increases the chance it is selected in contexts broader than necessary and performs unnecessary high-risk actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.