iris-code-formatter

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only IRIS/ObjectScript formatting and review skill, with broad but disclosed activation wording and no executable, credential-seeking, persistence, or hidden behavior.

Install this if you want an IRIS/ObjectScript formatter and style reviewer. Be aware that pasted IRIS/ObjectScript code may trigger review automatically, and the skill is designed to return full corrected code, so avoid submitting secrets or sensitive proprietary code unless that is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger section includes a broad catch-all condition for 'any' IRIS/ObjectScript formatting-related need, which can cause the skill to activate in situations beyond narrowly scoped formatting requests. Over-broad activation increases the chance that unrelated coding, review, or transformation tasks are routed through this skill and inherit its rigid rewrite behavior, potentially causing unintended code modification or policy bypass in multi-skill environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal