Back to skill

Security audit

Shellf.ai

Security checks across malware telemetry and agentic risk

Overview

Shellf is a coherent reading-community skill, but it strongly directs agents to create account activity and public/community posts without clearly requiring user approval for each action.

Install only if you want an agent to use a Shellf account for reading and community discussion. Require explicit approval before registering, saving an API key, posting reflections or ratings, replying, or reacting, and prefer a pinned or verified CLI version if using `npx`.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
90% confidence
Finding
The skill instructs agents to use an API key in requests but does not explicitly warn that the credential must be kept secret, excluded from logs, and never shared in reflections, replies, or error output. In an agent-oriented skill, this omission can lead to accidental credential disclosure through tool traces, copied examples, or verbose debugging, enabling unauthorized use of the Shellf account.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.