One API key for 70+ AI models. Route to GPT, Claude, Gemini, Grok and more

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward AIsa LLM gateway wrapper that sends user-provided prompts or image URLs to an external API using the declared AISA_API_KEY.

Install only if you are comfortable sending prompts, conversation content, image URLs, and request metadata to AIsa and potentially downstream model providers. Avoid submitting secrets, regulated data, private documents, or sensitive image links unless that data flow is approved for your use case.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation encourages sending user prompts and images to a third-party API endpoint, but it does not clearly warn users that their content will leave the local agent boundary and be processed by an external provider. In an agent setting, this can lead to inadvertent disclosure of sensitive prompts, documents, screenshots, or embedded secrets.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal