Back to skill

Security audit

linear-too组合包

Security checks across malware telemetry and agentic risk

Overview

This operations bundle is not deceptive, but it combines command execution, file writing, API credentials, and AWS-related automation without tight task boundaries or approval controls.

Review this bundle carefully before installing in any production or cloud-connected environment. Use least-privilege credentials, keep secrets in environment variables, prefer read-only or dry-run workflows first, and require explicit human approval before commands, file writes, AWS changes, or bulk processing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The bundle prominently advertises read/exec/write capabilities across multiple operations-focused skills without an equally prominent warning that these actions can modify files, execute system commands, and affect infrastructure. In an operations context, understated disclosure increases the chance that users invoke powerful actions on production systems without understanding blast radius.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The examples demonstrate writing output files and sending data via HTTP API calls with an authorization header, but they do not warn users about sensitive-data handling, credential exposure, or the consequences of transmitting operational data. Because this bundle targets operations workflows and includes exec/write capabilities, omission of nearby risk disclosure makes unsafe copy-paste use more likely.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The bundle use-case describes generic activation like using multiple member skills to 'complete related tasks' and then 'integrate outputs' while advertising read/exec/write capabilities, but it does not define any task boundaries, approval gates, or environmental constraints. In an operations bundle, this ambiguity can cause an agent to invoke powerful system-affecting tools too broadly or in unintended sequences, increasing the chance of unsafe automation or privilege misuse.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The manifest explicitly presents multiple Operations skills as offering exec and write capabilities, yet provides no user-facing warning that these actions may change systems, cloud resources, files, or monitoring configurations. In the context of an operations-oriented bundle that includes AWS-related tooling, lack of warnings and safety gating materially raises the risk of destructive commands, configuration drift, data loss, or unintended infrastructure changes.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.