Find Stl

Security checks across malware telemetry and agentic risk

Overview

The skill does what it says, but it should be reviewed because it downloads and extracts remote model files without strong local path and file-safety checks.

Install only if you are comfortable with a tool that downloads and extracts public 3D model archives. Use a dedicated output folder, avoid running it in sensitive directories, and inspect downloaded files before opening or printing them. The publisher should add path containment checks, file-type and size validation, and safer ZIP extraction before this is treated as routine.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill description advertises automatic searching, downloading, and manifest creation without clearly warning that it will retrieve remote content and write files locally. This can cause users or higher-level agents to trigger network activity and disk writes unexpectedly, which is a transparency and consent problem. The context makes the behavior functionally aligned with the skill's purpose, so the risk is lower, but it is still a valid safety issue.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal