← back to grpo-rl-training

SkillSpector · grpo-rl-training

independent scanner by NVIDIA · skill by qcmuu · how it works ↗

CAUTIONmax severity: MEDIUMrisk score: 28

Direct exec() call allows arbitrary code execution. An attacker can inject code that runs with the full privileges of the process.; Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

scanned 2026-08-23

Findings (2)

HIGHDangerous Code Executionconfidence: 0.425

Direct exec() call allows arbitrary code execution. An attacker can inject code that runs with the full privileges of the process.

examples/reward_functions_library.py

HIGHPrompt Injectionconfidence: 0.6

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

README.md

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTIONthis skill

Overall severity MEDIUM

WARNING

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete