Bug Hunter

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only bug-reporting skill, with a real but manageable risk of accidentally saving sensitive API data in debugging logs.

Safe to install as a bug-triage aid. Before saving or sharing debug logs, redact Authorization headers, cookies, tokens, API keys, passwords, session IDs, customer data, and sensitive request or response fields; prefer sanitized examples and approved storage for diagnostic artifacts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly tells users to save full API requests and responses for bug reports, but it does not warn about secrets and personal data that may be present in headers, bodies, tokens, cookies, or returned payloads. In a bug-analysis workflow, this creates a realistic risk of credential leakage or unauthorized retention of sensitive production data in logs and reports.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal