Back to skill

Security audit

Api Security Scanner

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only API security review checklist skill; it fits its stated purpose, but users should redact sensitive API details before use.

This skill is reasonable to install for API security review. Before using it, redact real bearer tokens, API keys, session cookies, private keys, internal-only hostnames, customer data, and private vulnerability details unless you have approval to share them with the AI environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The README explicitly encourages users to paste API endpoints, gateway or framework configurations, and vulnerability findings, but provides no warning to avoid secrets, production credentials, tokens, private URLs, or sensitive incident data. In a security-scanning skill, that omission increases the chance that users disclose confidential material to the agent or downstream systems, creating avoidable data-exposure risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.