Happenstance

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Happenstance API helper that clearly uses a Happenstance API key and curl to search professional-network data, with no hidden code or persistence found.

Install this only if you intend to let your agent use your Happenstance account. Treat the API key like a password, check credit balance before bulk searches, and avoid using the skill to research people or share profile details unless you are authorized and comfortable sending that information to Happenstance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs users to search their professional network and research people using connected-network data and external profile details, but it provides no privacy notice, consent guidance, or limitation on appropriate use. This increases the risk of misuse for non-consensual profiling, inappropriate employee surveillance, or sharing personal data beyond user expectations.

Missing User Warnings

Low
Confidence
91% confidence
Finding
The authentication section demonstrates direct Bearer-token usage but does not warn against exposing the API key in logs, screenshots, shell history, shared terminals, or error output. While the examples are standard, omission of credential-handling guidance can lead to accidental token disclosure and unauthorized API use.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal