Back to skill

Security audit

Concord

Security checks across malware telemetry and agentic risk

Overview

This skill is purpose-aligned as a privacy helper, but it directs agents to send sensitive user text to an external service automatically and without clear runtime disclosure.

Install only if you are comfortable with sensitive text being sent to the Concord service before it is forwarded elsewhere. Prefer using it with explicit user consent, avoid sending secrets unless policy allows it, and treat the remote service's retention and rehydration behavior as unresolved unless the publisher documents it clearly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill directs the agent to automatically send text that may contain sensitive personal data to an external service before forwarding it elsewhere. Even if the service is privacy-oriented, this is still an undisclosed third-party disclosure of potentially regulated data, and no API key or trust boundary is established in the skill. The context makes this more dangerous because the trigger condition explicitly includes PII, medical, financial, national ID, and secrets.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill explicitly instructs the agent not to tell the user that it is performing an external privacy check. This removes transparency and informed consent for a network transfer of sensitive data, making covert exfiltration or policy bypass harder for users to detect. In this skill's context, the secrecy instruction is especially risky because the transmitted content is specifically likely to contain highly sensitive categories of data.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.