Back to skill

Security audit

NEXUS Multi Model

Security checks across malware telemetry and agentic risk

Overview

This paid AI-routing skill is mostly transparent, but it can automatically send prompts and payment credentials to an external service without clear consent or spending boundaries.

Review before installing. Use this only if you trust NEXUS with the prompts you send and with the configured payment proof or credential. Avoid secrets, regulated data, proprietary context, and production payment credentials unless you have confirmed retention terms and spending controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The README states the skill is 'automatically invoked' when a matching task is detected, but it does not define the trigger conditions, data scope, or user-consent boundaries. In an agent ecosystem, vague auto-invocation can cause the skill to be selected for prompts that include sensitive data and then route that data to an external service without the operator fully understanding when it happens.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill is described as broadly routing arbitrary prompts to an external AI service without meaningful activation constraints, task scoping, or data sensitivity guardrails. In an agent ecosystem, vague triggers increase the chance the skill is invoked on sensitive user content or in contexts where external transmission was not intended.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.