科技资讯日报

Security checks across malware telemetry and agentic risk

Overview

This skill fetches technology and AI news from disclosed external sources, with no hidden persistence or local data access found.

Install this if you are comfortable with the agent making external search or website requests when you ask for technology news. If you configure TAVILY_API_KEY, use an appropriately scoped key and expect quota/account-linked API usage. Only add the cron example if you intentionally want recurring daily runs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrases are broad enough to match many ordinary requests for tech news, which can cause the skill to activate unexpectedly. Over-broad invocation is a security and safety concern because it increases unintended network access, external data retrieval, and possible interference with user intent, especially in agents that auto-select skills.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal