Back to plugin

Security audit

Evidencecraft

Security checks across malware telemetry and agentic risk

Overview

This is a transparent reporting-workflow skill bundle that writes local report artifacts and can coordinate scoped subagents, with no evidence of hidden install code, credential use, or exfiltration.

Install this if you want structured evidence-report workflows. Expect it to read relevant project evidence, create local Markdown governance files and reports, and optionally use scoped worker/reviewer agents when a confirmed plan selects that path. Review the generated plan before confirming execution, especially the listed source access, write paths, final save path, and whether multi-agent delegation is appropriate for your data sensitivity.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Hidden Instructions

High
Category
Prompt Injection
Content
<!-- Template use: render every heading, label, table header, placeholder replacement, and narrative passage in the confirmed artifact language. The sample title's “Report Plan” phrase is a translatable artifact-type label, not a canonical identifier. Preserve canonical codes and IDs, exact Skill names, paths, hashes, citations, code, formulas, and original source titles. Remove this and every Template instruction comment from the instantiated artifact. -->

# Report Plan: [topic]
Confidence
70% confidence
Finding
<!-- Template use: render every heading, label, table header, placeholder replacement, and narrative passage in the confirmed artifact language. The sample title's “Report Plan” phrase is a translatab

Hidden Instructions

High
Category
Prompt Injection
Content
- Delegation: safe | unsafe — [reason and context boundary]
- Downstream consumers: [WP IDs/report/reviewer]

<!-- Template instruction: repeat only for independently reviewable deliverables. -->

## Synthesis and claim discipline
Confidence
70% confidence
Finding
<!-- Template instruction: repeat only for independently reviewable deliverables. -->

Hidden Instructions

High
Category
Prompt Injection
Content
## Findings

<!-- Template instruction: repeat for every finding; if none, state the artifact-language equivalent of `No findings`. -->

### RV-<id>: <title>
Confidence
91% confidence
Finding
<!-- Template instruction: repeat for every finding; if none, state the artifact-language equivalent of `No findings`. -->

Hidden Instructions

High
Category
Prompt Injection
Content
<!-- Template use: render every heading, label, table header, placeholder replacement, and narrative passage in the confirmed artifact language. The sample title's “Analysis Review Report” phrase is a translatable artifact-type label, not a canonical identifier. Preserve canonical verdict/status codes and IDs, exact Skill names, paths, hashes, citations, code, formulas, and original source titles. Remove this and every Template instruction comment from the instantiated artifact. -->

# Analysis Review Report
Confidence
94% confidence
Finding
<!-- Template use: render every heading, label, table header, placeholder replacement, and narrative passage in the confirmed artifact language. The sample title's “Analysis Review Report” phrase is a

Hidden Instructions

High
Category
Prompt Injection
Content
## Main Agent verification

<!-- Template instruction: complete after receiving the independent report; do not let the reviewer fill this section. -->

- Material findings checked against actual artifacts:
- Feedback reclassified or rejected with counter-evidence:
Confidence
96% confidence
Finding
<!-- Template instruction: complete after receiving the independent report; do not let the reviewer fill this section. -->

VirusTotal

64/64 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.