Pihole Ctl

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a coherent local Pi-hole management helper, with expected local service-control risk but no evidence of hidden or malicious behavior.

Install only if you intend to let an agent help manage your local Pi-hole. Treat blocking toggles, gravity updates, and other Pi-hole CLI operations as live network changes, and require explicit confirmation before running state-changing or sudo commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The skill advertises service-control actions like enabling/disabling blocking and updating gravity without explicitly warning that these commands change live system behavior and may require elevated privileges. In an agent setting, that can lead to unintended operational changes, disruption of DNS filtering, or execution of privileged commands without sufficiently informed user consent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal