Dataify Google News

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Dataify Google News API helper that asks for confirmation before calling the service, with token-handling risks users should manage carefully.

Install only if you intend to use Dataify for Google News searches. Set DATAIFY_API_TOKEN in the environment when possible instead of pasting the token into chat or command arguments, review the confirmation table before approving calls, and remember that your news query parameters will be sent to Dataify.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger description is overly broad: phrases like "news search/information" and references to mentioning a "news search field" could cause the skill to activate during ordinary conversation rather than clear user intent. In an agent setting, ambiguous activation increases the chance of unintended external requests, parameter collection, or workflow hijacking when the user did not explicitly ask to use this skill.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill mandates a specific user-facing table schema using Chinese column names (`参数名`, `当前值`, `默认值`, `说明`) without checking the user's language preference. While not directly leading to code execution, forcing output language can confuse users during confirmation, undermine informed consent, and increase the risk of accidental approval of an API call.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal