Back to skill

Security audit

Ai Receptionist

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Solvea onboarding guide, but it steers broad customer-support requests into a third-party signup flow and sensitive integrations without enough consent or privacy guidance.

Review before installing. Use it only if you specifically want Solvea, verify the solvea.cx domain and current pricing independently, avoid uploading confidential or regulated documents until you understand retention and access controls, and connect email, phone, Shopify, Calendar, or Sheets only with limited test accounts or least-privilege permissions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are broad enough that the skill could activate on common support-automation requests without clear user intent to use this specific third-party service. That can steer users into an external signup and deployment flow unexpectedly, increasing the chance of accidental vendor promotion, unwanted navigation, or data disclosure to the service.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill directs the agent to immediately open external sites in the user's browser and even says to do so proactively, without first obtaining explicit consent or warning that a third-party site will be launched. In this context, that creates a risky pattern of automatic navigation to external services and conditions users to trust unprompted browser actions.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill asks the user to extract and share a `personaId` from the browser URL, which is likely an account- or resource-linked identifier, without explaining its sensitivity or minimizing exposure. Sharing internal identifiers into chat can leak tenant-specific information and may enable unauthorized deep-linking, support impersonation, or correlation of the user's account resources.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.