Back to skill

Security audit

API Tester Pro

Security checks across malware telemetry and agentic risk

Overview

This API-testing skill does what it says, but users should avoid sending secrets or private endpoints unless they intend to test them.

Install only if you are comfortable with a tool that sends requests to endpoints you choose and keeps local request history. Do not test private services, authenticated APIs, tokens, or sensitive payloads unless you intend those values to reach the target endpoint and are comfortable with the URL/status/error history being stored locally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill performs outbound HTTP requests and persists request history locally, but the user-facing description does not clearly warn that user-supplied URLs, headers, bodies, and response metadata may be transmitted to external services and stored on disk. In an agent context, this can lead to unintended disclosure of sensitive endpoints, tokens, payloads, or internal service information, especially when users test private APIs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.