Back to skill

Security audit

Files

Security checks across malware telemetry and agentic risk

Overview

This appears to be a Tencent Cloud automation skill, but its user-facing metadata still looks like a file utility while the instructions can manage real cloud resources.

Review this carefully before installing because it is not just a file-related skill: it guides an agent to authenticate to Tencent Cloud and run commands that can create or change cloud resources. Only use it if you intend to manage Tencent Cloud, and require explicit confirmation before any non-read-only command.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly documents cloud resource creation and modification flows, including instance provisioning and disk resize discovery, but does not require confirmation gates, impact warnings, or guidance to verify target resources before execution. In a cloud automation context, this increases the risk of unintended cost-incurring or service-affecting operations if an agent follows the examples directly.

Missing User Warnings

Low
Confidence
91% confidence
Finding
The document instructs users to perform live network retrievals with curl against an external domain, but it does not warn that these requests contact third-party infrastructure and may expose metadata such as IP address, access timing, or any user-supplied query terms embedded into commands. In a cloud automation skill, operators may copy commands directly into trusted environments, so the lack of disclosure increases the chance of unintended outbound traffic and context leakage.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.