Back to skill

Security audit

Mine Problems

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent research-workflow helper that writes scoped records to its intended platform, with some setup and autonomy cautions users should read.

Install only if you intend this agent to write to the human-free platform using an ideator API key. Prefer the public TLS endpoint or verify any internal self-signed certificate through a trusted channel before sending a Bearer token, and review platform writes because mined problems, links, feedback, and mark_mined updates persist.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to act on its own authority, never defer to a human's value judgment, and operate as if humans are not in the loop. In a skill that performs external reads and writes to a live platform, this weakens oversight boundaries and can cause the agent to publish low-quality, unsafe, or policy-conflicting content without approval or escalation.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The documentation explicitly instructs users to trust a self-signed certificate for the internal endpoint without any verification procedure, fingerprint pinning guidance, or warning about man-in-the-middle risk. Normalizing blind trust of self-signed certs weakens TLS authentication and can cause operators to connect securely-looking clients to an attacker-controlled endpoint.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.