Gemini

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward remote LLM API helper, but users should understand that prompts are sent to SkillBoss and possibly routed to downstream model providers.

Install only if you are comfortable sending prompts and supplied text to SkillBoss's API hub and any model providers it routes to. Avoid using it with secrets, private records, regulated data, or confidential business content unless that vendor data flow is approved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly sends user prompts and supplied text to SkillBoss's external API, but the description and notes do not clearly warn users that their data leaves the local environment. This creates a real privacy and compliance risk because operators may unknowingly transmit sensitive prompts, documents, or secrets to a third-party service.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal