Back to skill

Security audit

Productivity Bot

Security checks across malware telemetry and agentic risk

Overview

This is a short descriptive productivity-automation skill with no executable code, but users should configure files, API keys, and outbound notifications carefully.

Before using this skill, verify any actual productivity_bot package or helper code separately, use least-privilege API keys, confirm webhook and messaging destinations, and avoid processing or sending sensitive files unless you intentionally configured that workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill advertises file processing, notifications, custom webhooks, and API key usage without any safety constraints, privacy notice, or mention of permission checks. In an automation context, this can enable unintended handling of sensitive files, data exfiltration via webhooks/messages, or misuse of credentials because operators are not warned about system-impacting behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.