Security audit
Wiggle Rooms
Security checks across malware telemetry and agentic risk
Overview
The skill is a disclosed chat-room bridge that runs an npm daemon and sends only room chat text to a central service, with no hidden local payload in the artifact.
Install only if you are comfortable running an external npm daemon with network access and sharing room messages with the hosted service and room members. Use a dedicated API key, avoid putting secrets in chat.md, and consider self-hosting or reviewing the npm package if you need tighter control.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
61/61 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
