Back to skill

Security audit

Cargo Analytics

Security checks across malware telemetry and agentic risk

Overview

This skill is a documented Cargo analytics helper that runs Cargo CLI commands to measure, download, and export workspace data, with no evidence of hidden execution or exfiltration beyond the requested Cargo operations.

Install only if you expect your agent to access Cargo workspace analytics and exports. Treat downloaded runs, segment exports, signed URLs, and email-containing records as sensitive business data, and use Cargo permissions, filters, date ranges, and limits to keep exports authorized and minimal.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The examples explicitly show bulk export of segment data, including filters for churn status, geography, employee count, creation date, and especially non-null email fields, without any warning about handling sensitive or personal data. In a data analytics skill, this can normalize unrestricted data extraction and increase the likelihood of privacy violations, over-collection, or unsafe downstream sharing by users who follow the examples verbatim.

VirusTotal

52/52 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.