StripFeed

Security checks across malware telemetry and agentic risk

Overview

StripFeed is a coherent URL-to-Markdown helper that uses an external API, with a privacy disclosure gap but no evidence of hidden or malicious behavior.

Install only if you are comfortable sending target URLs and fetched page content to StripFeed's external service. Avoid using it for internal systems, private documentation, authenticated pages, signed URLs, URLs containing tokens, or regulated data unless you have explicit approval and understand the provider's retention and caching behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill recommends use for essentially any need to read a web page or URL, making it likely to be invoked broadly and automatically. In an agent setting, that increases the chance that sensitive, internal, or user-provided URLs are sent to a third-party service without sufficient scrutiny or consent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation explains authentication but does not clearly warn that requested URLs and associated metadata are transmitted to stripfeed.dev for processing. This omission can cause unintentional disclosure of sensitive browsing targets, query strings, document locations, or access patterns to an external provider.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal