AIOT Network

Security checks across malware telemetry and agentic risk

Overview

The skill is a transparent AIOT router, but it points users toward sensitive identity, payment, card, and crypto workflows that should be reviewed separately.

Before installing, review the individual AIOT sub-skills, verify the API base URL, and require clear confirmation before uploading identity documents, creating cards, sending money, converting currency, staking, or withdrawing crypto.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill describes account, KYC, payment, banking, wallet, and crypto flows that inherently involve highly sensitive personal and financial data, and it defines a default external API base URL, but it does not provide any user-facing warning or consent guidance about transmitting that data. In this context, omission of disclosure is risky because users may not realize their identity, financial, or crypto information will be sent to remote services.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal