Security audit
iaiops-factory
Security checks across malware telemetry and agentic risk
Overview
The skill is a disclosed industrial-operations helper with high-impact write capabilities, but those capabilities are purpose-aligned and described as gated, dry-run-first, and approval-controlled.
Install only in environments where the operator is authorized to inspect or control industrial systems. Keep write tools disabled unless a real MOC process, named approval, dry-run review, and rollback plan are in place, and restrict root/raw-socket use and API tokens to the specific factory network or gateway being assessed.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
