Poem

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple reference tool that prints static Poem documentation and shows no evidence of credential use, network access, persistence, or system changes.

This appears reasonable to install as a lightweight documentation/reference skill. It does include an executable shell script, so users should still treat it as executable content, but the inspected script only prints static reference text and does not request sensitive access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal