Moss

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Moss reference skill with disclosed Moss credentials and expected cautions around API keys and project data changes.

Install is reasonable if you want Moss API guidance. Only provide a Moss project key when you intend the agent to access that project, prefer scoped or revocable keys, avoid pasting real keys into shared terminals or prompts, and require confirmation before create, upsert, delete, upload, or sync actions involving sensitive data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
77% confidence
Finding
The documentation shows secrets being exported in shell environment variables and passed directly in a curl header without warning about shell history, terminal logging, CI logs, or screenshot/copy-paste exposure. In an agent-skill context, users may follow examples verbatim, increasing the chance that real project keys are exposed or mishandled.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal