Back to skill

Security audit

Pub Brave

Security checks across malware telemetry and agentic risk

Overview

The skill is presented as Brave Search but actually grants broad SkillBoss/HeyBossAI API access, including email and SMS actions, so users should review it carefully before installing.

Install only if you intentionally want a broad SkillBoss/HeyBossAI multi-provider gateway, not a narrow Brave Search tool. Use a limited or spend-capped API key if possible, avoid submitting sensitive documents, audio, images, prompts, phone numbers, or email content unless the provider terms are acceptable, and require explicit user approval before any email or SMS action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The manifest presents this as a Brave Search/content-extraction skill, but the body actually documents a general SkillBoss API with many unrelated capabilities. This mismatch can mislead users and higher-level policy controls into granting a much broader capability surface than expected, increasing the chance of unsafe use or review bypass.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
Including email-sending in a skill advertised as Brave Search materially expands the action surface from read/search into outbound communications. That can enable spam, phishing, data exfiltration, or unauthorized message sending under a misleading skill identity.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
SMS/OTP features are unrelated to the stated search purpose and introduce sensitive identity and verification workflows. Such capability can be abused for unsolicited messaging, verification abuse, or social-engineering support, especially when hidden inside a search-branded skill.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Image, video, audio, music, and transcription functions substantially broaden the skill beyond Brave Search and content extraction. While not inherently malicious, the unexplained expansion weakens least-privilege expectations and makes it easier to funnel arbitrary user data to external providers under a narrower-looking label.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Background removal and document processing are unrelated to the declared Brave Search purpose and can involve uploading sensitive files or images to external services. Hidden extra processing features increase the risk of accidental disclosure and capability overreach.

Intent-Code Divergence

Medium
Confidence
99% confidence
Finding
The skill is framed as Brave Search, but the content immediately pivots to SkillBoss and a different API endpoint. This identity mismatch undermines trust and reviewability because operators may approve or invoke the skill based on one brand/purpose while actually using another external service.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The documented capabilities substantially exceed the stated scope of a Brave Search API skill by advertising scraping, screenshots, Amazon/LinkedIn/YouTube data access, and CEO interview feeds. This kind of scope mismatch can mislead users and downstream agents into invoking data collection or third-party services they did not consent to, weakening trust boundaries and increasing the chance of privacy, compliance, or policy violations.

Description-Behavior Mismatch

Low
Confidence
88% confidence
Finding
The web search section presents multiple non-Brave providers under a Brave Search-focused skill, creating a deceptive or at least confusing representation of backend behavior. Even without code execution, this can cause users or orchestrators to route queries to unexpected external providers, which may alter data handling, logging, and compliance expectations.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The documented capabilities significantly exceed the stated purpose of a Brave Search/web extraction skill, indicating scope creep and a misleading skill boundary. This is dangerous because users or downstream agents may grant trust or invoke the skill expecting only search behavior, while the documented models enable unrelated actions such as messaging and document handling.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
Email and SMS sending are active outbound communication capabilities that are not justified by a search/content extraction skill. If exposed through a misleadingly scoped skill, they could be abused for spam, phishing, OTP abuse, or data exfiltration under the guise of a benign search tool.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Embeddings, document parsing, and presentation generation are unrelated to the stated Brave Search purpose and expand the skill's data-processing scope beyond user expectations. This increases the risk of inappropriate data ingestion, retention, or transformation and makes security review and permissioning less reliable.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill documents document upload, email, and SMS/OTP operations without any warning that user content and recipient data are transmitted to external services. Lack of disclosure is dangerous because these actions may handle sensitive files, contact details, and verification data that users may not expect to leave the local environment.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.