Back to skill

Security audit

搜索并播放电影,支持按类型/年份/评分筛选,中英文输入,生成 iframe 播放页面

Security checks across malware telemetry and agentic risk

Overview

This skill openly searches for movies and generates playable pages, but it directs agents to use unvetted third-party streaming embeds and does not give users enough warning or control over that risk.

Review carefully before installing. This skill may create local pages that load third-party streaming sites in your browser, which can expose your IP/browser data, show unsafe content, or raise copyright/legal issues. Prefer a version limited to metadata and authorized streaming providers, with explicit confirmation before any playback page is generated.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The skill explicitly instructs the agent to construct third-party movie streaming embed URLs and, if needed, search for 'watch online free embed' sources. This goes beyond benign metadata lookup and operationalizes access to unauthorized streaming sources, creating legal, policy, and supply-chain risk from untrusted third-party embeds.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill is presented as a 'Movie Finder' but its core behavior includes generating local watch pages with embedded players and source switching for third-party streams. This mismatch is dangerous because it obscures the real capability from reviewers and users, increasing the chance that unauthorized streaming behavior is deployed without proper scrutiny or consent.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation examples are generic natural-language requests like wanting to watch a sci-fi movie, which can easily overlap with ordinary conversation and cause unintended skill activation. In a skill that can search the web and generate playable HTML pages with embedded external sources, accidental invocation increases the chance of exposing users to unreviewed content or unsafe playback pages.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The installation/feature description states that the skill generates local HTML pages with embedded iframe players and multiple external playback sources, but it does not warn users about the security and privacy implications of loading third-party media content locally. This is dangerous because embedded external sources can track users, serve malicious content, or exploit browser behavior, especially when users are encouraged to open generated pages without understanding the risks.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill directs the agent to generate local HTML files containing third-party iframes and present them to the user, but does not require a clear upfront warning about loading untrusted external content. This exposes users to deceptive or unsafe embedded content, tracking, and possible browser-side abuse from third-party domains framed as part of the assistant workflow.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.