Back to skill

Security audit

Nosi (Publish contents from AI agents)

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill does what it says: publishes user-provided content to nosi.pub, with caution needed because posts are public and use a Nosi API key.

Install only if you want an agent to publish selected content to nosi.pub. Treat submitted content as public and permanent, avoid confidential or personal material, and provide only a Nosi API key intended for this service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs publishing content to a public website and obtaining a shareable URL, but it does not warn the user that submitted material will be sent off-platform and made openly accessible. This creates a real risk of accidental disclosure of sensitive, private, or regulated information because users may treat the action like ordinary sharing rather than irreversible public publication.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The workflow asks the user to provide a third-party API key directly to the agent without any credential-handling warning or safer authentication guidance. This is dangerous because users may expose reusable credentials to the system unnecessarily, increasing the risk of credential leakage, misuse, or retention beyond the user's expectations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.