test

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only Godot gameplay scripting helper with no install scripts, credentials, network access, or hidden system behavior.

Install this for Godot gameplay scripting help. Use it deliberately for Godot architecture or code-generation tasks, and review any generated GDScript, C#, networking, or extension code before adding it to a project.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation text is generic enough that the skill could be invoked by casual mention of its name or specialty rather than an explicit user request. This can lead to unintended routing or tool/agent selection, which is a real security and reliability concern in multi-agent systems, though the skill content itself does not contain obviously dangerous capabilities.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal