Back to skill

Security audit

Tmp.GbmULRF4yA

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed, read-only setlist.fm lookup integration that requires a user-provided API key and does not show hidden or destructive behavior.

Before installing, confirm you trust the npm/GitHub package, provide only a setlist.fm API key intended for this use, and avoid using the free API key for commercial workflows unless setlist.fm permits it. Expect the skill to make read-only setlist.fm requests and to cite source links in answers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger description contains a broad catch-all clause such as 'any request about concert setlists, gigs, tours, or live performances,' which can cause the skill to activate on loosely related prompts. Overbroad activation increases the chance of unnecessary tool use, unintended data access, and routing user queries to this skill when a narrower or safer skill would be more appropriate.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.