mac trans

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward translation helper, but anything translated through Bing may be sent outside the user's computer.

Install only a trusted translate-shell/trans package, confirm the command is the expected binary, and use this skill only for text or files you are comfortable sending to Bing or another online translation provider. Redact secrets and confidential information first, or use a local/offline translation option for sensitive material.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
79% confidence
Finding
The skill description is very broad and does not constrain when the agent should invoke it, which increases the chance of the tool being used automatically on arbitrary user-provided content or files. In this skill, that ambiguity matters more because the tool can send text or file contents to an external translation backend, creating unintended data disclosure risk.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation explicitly encourages translating entire file contents but does not warn that the contents may be transmitted to an external translation service such as Bing. This can lead to sensitive data, secrets, proprietary documents, or personal information being exfiltrated to a third party when users or agents translate local files.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal