Security audit
Iaiops Energy
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed, read-only utility telemetry integration for energy and substation monitoring, with no artifact evidence of hidden writes, exfiltration, or persistence.
Install only in an authorized utility or lab environment, configure only approved endpoints, keep credentials in the described secret manager rather than chat or config files, and remember that even read-only polling can affect production links if used carelessly.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
