Tmp.FZKTvFaGeu

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Etix lookup helper, but it depends on an external MCP package and browser extension that use your active Etix browser session.

Install only if you are comfortable trusting the etix-mcp npm package and fetchproxy extension. Keep Etix-specific prompts explicit, and remember that requests are made through your own browser tab, cookies, TLS, and session.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger description is broad enough to match generic requests involving events, venues, performers, or showtimes, which can cause the skill to activate when the user did not specifically intend to use Etix. In this skill, unintended invocation is more concerning because activation can lead to requests being routed through the user's live browser session and extension bridge, increasing the chance of unnecessary exposure of session context or unintended third-party interaction.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal