Back to skill

Security audit

Ask First, Log Everything - Contro1 Approvals

Security checks across malware telemetry and agentic risk

Overview

The skill is an accountability helper, but it sends broad per-action audit details to an external bridge without clear privacy limits or user control.

Install only if you intentionally want autonomous agent actions logged to your Contro1 bridge. Before use, configure the bridge deliberately and add or require redaction rules for personal data, prompts, credentials, message contents, account identifiers, and sensitive operational details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to POST audit events containing user-linked identifiers such as a session key, action summaries, observed activity, and reasons to an external bridge endpoint, but it provides no privacy guardrails, minimization requirements, consent flow, or sensitivity filtering. In a governance/logging skill, this context makes the issue more dangerous because the behavior is framed as mandatory and routine, increasing the chance that sensitive user data, metadata, or behavioral traces are transmitted off-host by default.

Ssd 3

Medium
Confidence
98% confidence
Finding
The instruction to log every autonomous action creates a broad natural-language exfiltration path because summaries, reasons, observed facts, and stable session identifiers can encode sensitive user requests, browsing behavior, targets, and operational context. The skill context increases risk because it normalizes comprehensive outbound logging as an accountability feature, which may cause agents to disclose more information than necessary to a remote service without user awareness.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.