Landing

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple local landing-page helper whose behavior matches its stated purpose, with minor disclosure and output-safety caveats.

Install only if you are comfortable running a small local bash helper. Be aware it creates ~/.local/share/landing, may activate broadly for web-page creation requests, and does not escape generated HTML content, so review output before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is broad enough to trigger on common web-page creation requests, which can cause the skill to activate in contexts the user did not explicitly intend. Over-broad activation increases the chance of unexpected command execution paths and unintended access to local tooling or stored data associated with the skill.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The file states that data is stored persistently in ~/.local/share/landing/ but does not indicate any user confirmation, notice at write time, or controls over what is retained. Persistent local storage can capture user content or metadata beyond the current session, creating privacy and retention risks if users are unaware.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal