Back to skill

Security audit

Dawn Search Suite

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed search and scraping helper with no executable install code, persistence, or hidden data handling found in the artifacts.

Before installing, understand that this skill may fetch and extract content from third-party sites, including dynamic pages. Use it only for public or authorized resources and respect applicable terms, robots policies, and privacy constraints.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly offers web search, URL extraction, and JS-rendered page scraping, but the description does not warn users about collection behavior, third-party content handling, or site-policy/legal considerations. In a scraping-focused skill, missing disclosure increases the risk of unauthorized or unexpected data extraction and unsafe use against sensitive or restricted targets.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.