Datayes 宏观指标

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Datayes macro-data helper that uses a user-provided API token only for Datayes/related data requests.

Install only if you are comfortable using a Datayes API token with this script. Use a scoped and revocable token where possible, do not paste or print the token in chats or logs, avoid shared shell environments, and rotate the token if it may have been exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill instructs users to place a live API token in an environment variable and states the script will automatically send it as a Bearer token, but it does not warn that the token is sensitive or should not be echoed, logged, pasted into transcripts, or set in shared environments. In agent and shell-assisted workflows, this omission can lead to credential leakage through terminal history, debug output, screenshots, or shared session logs.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal