Back to skill

Security audit

Tmp.Wpc8FjjT69

Security checks across malware telemetry and agentic risk

Overview

The skill documents Zillow data-fetching commands through a user-approved browser bridge, including disclosed access to signed-in saved homes and searches.

Install only if you are comfortable with fpx and the fetchproxy extension using your active Zillow tab. Treat saved searches and favorited homes as private account data, avoid logging or persisting those results unless needed, and remove or re-pair the profile if you no longer want that access to persist.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly enables access to Zillow data through the user's signed-in browser tab, including saved searches and saved homes, which are privacy-sensitive account artifacts. While the behavior is described, the documentation does not prominently warn users that running these commands can expose authenticated personal data to scripts, logs, or downstream tooling, so a user may invoke it without understanding the privacy implications.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The document explicitly describes how to access signed-in Zillow saved searches and favorited homes through an ambient authenticated browser session, but it does not warn that these endpoints expose private account data tied to the current user. In an agent skill context, that omission is dangerous because downstream agents or scripts may retrieve sensitive personal preference, location, and property-interest data without clear user awareness or consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.