Back to skill

Security audit

Modern URL shortening with QR codes and detailed analytics

Security checks across malware telemetry and agentic risk

Overview

This appears to be a straightforward Jo4 URL-shortener integration, with normal cautions around API-key access and deleting links.

Install if you are comfortable giving an agent access to your Jo4 API key. Prefer a revocable or dedicated key if available, review analytics output as potentially privacy-sensitive, and require explicit confirmation before updating or deleting existing short links.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill explicitly advertises analytics that expose visitor data such as geography, device/browser details, and referrer sources, but it provides no privacy notice, consent guidance, retention limits, or warnings about handling potentially personal data. In a user-invocable skill, this can encourage collection or disclosure of regulated or sensitive telemetry without informing operators of compliance obligations.

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The skill documents a delete endpoint for URLs without warning that the action may be irreversible or may remove associated analytics and QR-code availability. This increases the chance of accidental destructive actions by users or agents invoking the skill without confirmation safeguards.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.