码虫日报watcher

Security checks across malware telemetry and agentic risk

Overview

The skill appears purpose-aligned, with the main caveat that Feishu alerts may include operational details such as cron status, diagnostics, timestamps, and file paths.

Install if you are comfortable sending operational alerts to Feishu. Configure the destination deliberately, avoid including secrets or sensitive paths in alert payloads, and confirm any cron or scheduled alerting behavior matches your expectations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill documents sending Feishu alerts containing operational details such as timestamps, cron status, diagnostic information, and file paths, but it does not prominently warn that this data is transmitted to an external service. Even if the content is operational rather than secret, external transmission of internal state can expose infrastructure details or leak sensitive paths and failure metadata.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal