Back to skill

Security audit

Gpt

Security checks across malware telemetry and agentic risk

Overview

The skill mostly does what it claims, but its cost estimator can run local shell commands if given crafted token-count arguments.

Review before installing. The main risk is the cost command: do not pass untrusted or free-form values to --tokens or --output-ratio until the script validates numeric inputs and passes values to awk safely.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.