Back to skill

Security audit

Sharpagent Engineering Lifecycle

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only coding workflow skill with expected project-editing guidance and no hidden execution, credential use, persistence, or exfiltration behavior found.

Use this as a structured coding process, not as proof that changes are safe. Review the agent's diffs, keep backups or version control, and do not treat the skill's self-declared 'verified' label as independent security validation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill advertises applicability to 'structured development workflows of any scale' without clear activation boundaries, exclusions, or environment constraints. In an agent setting, this can cause overbroad invocation on sensitive, production, or safety-critical tasks where the workflow's generic guidance may be insufficient or may override more specialized controls, increasing the chance of unsafe autonomous actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.