SkillSpector · grpo-rl-training
independent scanner by NVIDIA · skill by qcmuu · how it works ↗
Direct exec() call allows arbitrary code execution. An attacker can inject code that runs with the full privileges of the process.; Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
scanned 2026-08-23
Findings (2)
Direct exec() call allows arbitrary code execution. An attacker can inject code that runs with the full privileges of the process.
examples/reward_functions_library.py
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
README.md
What the verdicts mean
SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.
Overall severity LOW (risk score in the safe range)
Overall severity MEDIUM
Overall severity HIGH
Overall severity CRITICAL
Scan could not complete