← back to system-audit

SkillSpector · system-audit

independent scanner by NVIDIA · skill by theheavenlyd3mon · how it works ↗

PASSmax severity: LOWrisk score: 17

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.; Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain…; Shadow Command Trigger: 'review versions' conflicts with built-in command 'review'

scanned 2026-08-23

Findings (3)

HIGHPrivilege Escalationconfidence: 0.18

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

references/post-update-sweep-checklist.md

MEDIUMRogue Agentconfidence: 0.6

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

SKILL.md

MEDIUMTrigger Abuseconfidence: 0.7

Shadow Command Trigger: 'review versions' conflicts with built-in command 'review'

SKILL.md

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASSthis skill

Overall severity LOW (risk score in the safe range)

CAUTION

Overall severity MEDIUM

WARNING

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete