Python code base64-encodes a local file and sends it over the network.
Critical
- Code
- suspicious.potential_exfiltration
- Location
- scripts/ai_guardian.py:39
Security audit
Security checks across malware telemetry and agentic risk
This skill is a disclosed cloud client for consented KYC face-liveness checks, with sensitive media upload behavior that matches its stated purpose.
Before installing, confirm you have authorization to process biometric media, set the endpoint only to a trusted HTTPS eKYC backend, understand that the selected face photo or video will be sent to that backend, and verify the backend's retention and access policies.
65/65 vendors flagged this skill as clean.
Detected: suspicious.potential_exfiltration