Byt Workflow

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do what it says: download YouTube audio and use Doubao desktop translation, but users should understand it saves files locally and drives a visible app window.

Install only if you are comfortable with the agent downloading media, saving outputs on disk, and controlling a visible Doubao desktop session. Use a dedicated workspace or desktop session for private content, avoid playing sensitive audio over speakers, and delete generated media and translation files when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill describes downloading YouTube audio and storing both media and translated text to disk, but it does not warn users that persistent local files will be created. This can expose copyrighted, sensitive, or private content to unintended retention, backup, sync, or access by other local users and processes.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The workflow uses GUI automation to launch Doubao, play audio, and capture translated subtitles, but it does not warn that this requires a visible desktop and may interact with on-screen applications or expose audio/text to the local environment. Without clear notice, users may run it in inappropriate contexts and unintentionally leak content through speakers, screen visibility, or automation acting on the wrong window.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal