Back to skill

Security audit

alon-fact-check

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only fact-checking skill whose web/search behavior fits its stated purpose, with the main caveat that users should avoid submitting sensitive URLs or text.

Reasonable to install for public or non-sensitive fact-checking. Do not paste confidential material or private/authenticated/internal URLs unless you are comfortable with the host agent using that content for web browsing or external searches, and verify the referenced npx/GitHub source if supply-chain provenance matters to you.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Confidence
92% confidence
Finding
The README states that URL inputs are read and then fact-checked, which implies outbound network access to retrieve the page and likely additional searches to authoritative sources, but it does not clearly disclose this as a privacy-relevant behavior to users. This can lead users to submit sensitive or internal URLs without understanding that the skill will access external content and perform network lookups.

Missing User Warnings

Low
Confidence
89% confidence
Finding
The README explains that pasted text is summarized and claims are searched against authoritative sources, but it does not warn that pasted content may be transformed into external queries or otherwise exposed to third-party services during fact-checking. Users may paste confidential text, assuming local-only processing, and unintentionally cause sensitive information to influence outbound retrieval or search activity.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.