Tmp.MhR5lJGw3L

Security checks across malware telemetry and agentic risk

Overview

This iOffice skill is not malware, but it can make real changes to workplace systems and does not clearly require confirmation before doing so.

Install only if you are authorized by your employer to automate iOffice/Eptura. Use the least-privileged account or token available, avoid username/password when a scoped token is possible, and require the agent to summarize the exact record and intended change before any create, update, delete, cancel, approve, check-in/out, archive, deliver, or return action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill exposes numerous state-changing and destructive operations such as create, update, delete, approve, cancel, check-in/out, archive, and deliver actions, but the documentation provides no guidance to require explicit user confirmation before executing them. In an LLM-agent context, this increases the risk of accidental or prompt-induced modifications to workplace data, including bookings, visitor records, maintenance workflows, moves, mail handling, and user/building records in a real enterprise tenant.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal