Security audit
Sharpagent Skill Contract
Security checks across malware telemetry and agentic risk
Overview
The reviewed skill artifacts are operational developer and moderation helpers whose powerful actions are disclosed, scoped to their stated workflows, and mostly gated by user intent.
Install only in trusted development or staff environments. Use the moderation commands carefully because they can affect real users and public content, prefer explicit confirmation before any write, and consider running autoreview with its no-yolo option or disabling fallback reviewers when working with sensitive private diffs.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
