Back to skill

Security audit

Danube Tools Marketplace

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Danube marketplace integration that needs an API key and can run external tools, with no hidden code or covert behavior found in the artifact.

Install this only if you want your agent to use Danube marketplace tools. Review each discovered tool's purpose and required parameters before running it, be especially careful with tools that write or delete user-scoped resources, and keep the Danube API key scoped, private, and revocable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill’s activation and operational guidance are extremely broad: it tells the agent to connect to a marketplace of services and to 'always search and explore' rather than limiting use to explicit user-approved tasks. This can cause overbroad tool discovery and execution behavior, increasing the chance of unsafe actions, unexpected data exposure to third-party services, or use of capabilities beyond user intent.

External Transmission

Medium
Category
Data Exfiltration
Content
env:
        - DANUBE_API_KEY
      bins:
        - curl
    primaryEnv: DANUBE_API_KEY
    homepage: https://danubeai.com
    always: false
Confidence
83% confidence
Finding
curl primaryEnv: DANUBE_API_KEY homepage: https://danubeai.com always: false --- # Danube — Connect Your Agent Danube is a marketplace that gives your AI agent access to a large and grow

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.