Back to skill

Security audit

NEXUS Teammate

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed paid remote AI service, but its broad automatic invocation and payment authority need review before use.

Install only if you trust NEXUS with the prompts, code, logs, and workflow data you send. Use sandbox testing first, restrict payment credentials, and require explicit human approval before sending confidential data or making any paid request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The README states the skill is 'automatically invoked' when a matching task is detected, but provides no trigger boundaries, approval requirements, or examples of safe versus unsafe invocation. For a skill that sends user input to a remote paid service, ambiguous auto-invocation increases the chance of unintended data disclosure and unexpected billing.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The README describes remote API usage and payment flows but omits any warning that prompts and possibly sensitive workspace data may be transmitted to an external host. Users and integrators may therefore enable or invoke the skill without understanding privacy, retention, jurisdiction, or billing implications.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill advertises itself as a general-purpose 'context-aware AI partner' for data processing, debugging, and workflows, with very broad usage language. This can cause the agent platform to invoke the skill for many unrelated prompts, increasing the chance that sensitive user data is unnecessarily routed to an external third-party service and paid endpoint.

Vague Triggers

Low
Confidence
92% confidence
Finding
The input is defined only as a required string named 'input' with the description 'The input text or query,' which provides no meaningful scope control. In combination with the broad skill description, this makes it easier for arbitrary user content—including secrets, regulated data, or irrelevant prompts—to be sent to the remote service without clear boundaries.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.