Back to skill

Security audit

Defect Prevention Expert

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent QA review helper, but it grants broader write and command authority than its documented tasks clearly need.

Review this before installing if you do not want a QA skill to have command execution or to update local knowledge-base files. It is best used only when you are comfortable approving report file creation explicitly and supervising any proposed changes to checklists, templates, or skill documentation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The manifest grants both write and execute capabilities, and the skill text explicitly instructs the agent to use write to generate files, but it does not present a clear safety boundary or require explicit consent before filesystem or command actions. In a broadly scoped QA skill, these permissions create unnecessary attack surface: adversarial user content or prompt injection embedded in reviewed artifacts could steer the agent into modifying workspace files or running commands beyond pure analysis.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill repeatedly instructs use of the write tool to generate files in the workspace, but does not clearly require explicit user consent immediately before filesystem modification or warn that local files may be created/overwritten. In an agentic environment, ambiguous auto-write behavior can lead to unintended file creation, overwriting review artifacts, or persistence of untrusted content, especially because the skill is designed to produce many report files across stages.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.