Console Patrol

Security checks across malware telemetry and agentic risk

Overview

This appears to be a bounded frontend console-audit helper, with broad trigger wording but no evidence of hidden, destructive, persistent, or data-stealing behavior.

Install only if you want an agent to inspect a web application's frontend console/runtime behavior. Use it on apps and routes you authorize, and review any dependency installs or browser-scanning steps before they run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrase 'Audit a web app' is broad enough to match many requests outside the narrow purpose of console error scanning, potentially causing this skill to activate for general security, code quality, or application review tasks. In an agent setting, overly broad invocation language can route unrelated prompts into a tool that installs packages, runs scans, and makes assumptions about target scope, increasing the chance of unintended actions.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The phrase 'Find issues in the application' is highly vague and can match a wide range of unrelated requests, from security testing to backend debugging, far beyond this skill's advertised console-analysis function. Because the skill also includes instructions to install dependencies and scan routes, ambiguous activation increases the risk of the agent performing unintended reconnaissance or environment changes under an overly general user request.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal