Back to skill

Security audit

eKYC Suite AI Guardian

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed cloud client for consented KYC face-liveness checks, with sensitive media upload behavior that matches its stated purpose.

Before installing, confirm you have authorization to process biometric media, set the endpoint only to a trusted HTTPS eKYC backend, understand that the selected face photo or video will be sent to that backend, and verify the backend's retention and access policies.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.potential_exfiltration

Python code base64-encodes a local file and sends it over the network.

Critical
Code
suspicious.potential_exfiltration
Location
scripts/ai_guardian.py:39