AiTun Tunnel

Security checks across malware telemetry and agentic risk

Overview

The skill’s public localhost-sharing capability is high impact but disclosed, purpose-aligned, and paired with user-confirmation guidance.

Install only if you intend to make a local app reachable by others. Before exposing a port, verify what is running there, avoid debug/admin/credential-backed services, and remove the route or stop the service when sharing is done.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This skill explicitly guides the agent/user to expose a local HTTP service to the public internet, but it does not include clear warnings about sensitive data exposure, authentication, access control, or the risks of tunneling development servers. That omission is dangerous because local apps commonly run with debug settings, weak defaults, or access to private files and internal APIs, so publishing them can unintentionally disclose data or enable remote abuse.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal