Back to skill

Security audit

Tmp.MbEkhi6Hfq

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed, read-only TripAdvisor lookup helper, with a browser-based fallback that users should handle carefully.

Before installing, be aware that the optional fpx fallback depends on your browser session and writes a TripAdvisor page to a temporary file. Use it only for pages you intend to fetch, avoid shared machines, delete temporary HTML after parsing, and do not share saved page files without checking them first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documented fallback instructs users to perform a browser-authenticated fetch against TripAdvisor and save the resulting page to a local file, but it provides no warning that the request executes in the context of a signed-in browser profile and may expose personalized or session-derived content in the saved HTML. Even if the target is a public page, the workflow increases the risk of local data retention, accidental sharing of session-influenced artifacts, and unintended handling of authenticated browsing data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.