Back to skill

Security audit

cloud-api-resource

Security checks across malware telemetry and agentic risk

Overview

This skill openly creates UCloud resources, but its broad trigger language and limited cost warning make it worth reviewing before installation.

Install only if you intend to let an agent help create UCloud resources. Use least-privilege subaccount keys, require an explicit UCloud/provider confirmation before any API call, carefully review the full resource and billing summary, and avoid providing broad or long-lived private keys in chat.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger condition is overly broad: any detected intent to 'create resources in UCloud' can invoke a skill that performs real cloud-side actions, including provisioning billable infrastructure and creating API keys. In an agent setting, this increases the chance of unintended or insufficiently scoped execution from ambiguous user phrasing, prompt injection in surrounding context, or mistaken intent classification.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill prominently advertises automatic creation of cloud resources and API keys without an up-front warning that these operations cause real external state changes, may incur charges, and may mint new credentials. In agent environments, users may treat the skill as advisory rather than operational, so the lack of conspicuous risk disclosure raises the likelihood of accidental resource creation, unexpected spend, and credential sprawl.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.