NEXUS Sentiment Analysis

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed paid remote sentiment-analysis skill with no local code execution, file access, persistence, or hidden install behavior.

Install only if you are comfortable sending the analyzed text to NEXUS and potentially paying per request. Avoid submitting secrets, regulated data, or confidential business content unless third-party processing is approved; use the sandbox payment proof for testing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The README states the skill is 'automatically invoked' when a matching task is detected, but does not define the trigger conditions or scope. That ambiguity can cause an agent or user to send unintended prompts or sensitive text to the remote service, increasing the risk of over-broad activation and privacy-impacting data disclosure.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README describes sending user input to a hosted API endpoint but does not warn that prompts/text are transmitted to a third-party remote service. In an agent setting, this omission can lead users or integrators to unknowingly expose sensitive or regulated content to an external provider.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal