Quantum News Digest

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed quantum-news API wrapper, but users should notice that it calls an unsecured raw-IP HTTP endpoint.

Install only if you are comfortable sending requests to an unauthenticated HTTP service at a raw IP address. Avoid sending sensitive prompts or private business data through it, and prefer a publisher-provided HTTPS domain before relying on it for important research or financial decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to call a raw HTTP endpoint by IP address, which exposes requests and responses to interception or modification in transit and provides no authenticity guarantees for the remote service. In the context of an agent skill, this is more dangerous because the endpoint may receive user queries or behavioral data, and users are given no warning about transport insecurity or privacy risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal