Perpetua

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed third-party OAuth proxy, but users should understand that connected service data may pass through Perpetua.sh when used.

Install only if you trust Perpetua.sh and the publisher with the connected account data. Use a rotatable API key, connect only the providers you need, avoid broad data pulls unless necessary, and revoke provider connections when you are done.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This skill handles highly sensitive personal health and calendar data and routes it through a third-party hosted API, but the description does not clearly warn users that their data will be transmitted externally. That omission can undermine informed consent and lead to unexpected disclosure of private data to an external service.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal