Back to skill

Security audit

FDE Delivery Loop

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed FDE delivery workflow suite with local, user-directed helper scripts and no evidence of hidden external actions or credential handling.

Before installing, expect this skill to create local delivery artifacts, project state logs, and optional runnable POC scaffolds when you ask it to. Do not put secrets or raw customer data into the state files or demo inputs, and require an architecture and authorization review before connecting any generated POC to real systems.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
fde-agent-skill-designer/assets/minimal-poc/poc-manifest.json:21