SkillSpector · system-audit
independent scanner by NVIDIA · skill by theheavenlyd3mon · how it works ↗
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.; Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain…; Shadow Command Trigger: 'review versions' conflicts with built-in command 'review'
scanned 2026-08-23
Findings (3)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
references/post-update-sweep-checklist.md
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
SKILL.md
Shadow Command Trigger: 'review versions' conflicts with built-in command 'review'
SKILL.md
What the verdicts mean
SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.
Overall severity LOW (risk score in the safe range)
Overall severity MEDIUM
Overall severity HIGH
Overall severity CRITICAL
Scan could not complete