Back to skill

Security audit

buildstack-site-builder

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed BuildStack website-management skill, but users should treat its publish and edit actions as live public-site changes.

Install this only if you want an agent to create and modify BuildStack websites. Review generated content before publishing, ask for a preview or explicit confirmation before live changes, and keep BUILDSTACK_API_KEY secret; rotate it if it appears in chat, logs, screenshots, or command history.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The README promotes one-shot site creation, publishing, and maintenance actions directly from chat, but it does not warn that these operations can make immediate live changes to public websites. In an agentic context, this increases the risk of accidental or unclear user authorization, leading to unintended publication, defacement, or domain/content changes on user-facing properties.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill enables creation, deployment, and modification of live websites and content, but it does not instruct the agent to confirm with the user before making state-changing actions or warn that these operations can immediately affect public-facing sites. In this context, an agent could unintentionally publish or alter live content, causing business, reputational, or operational harm.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs use of a bearer API key for authenticated requests but does not include guidance to treat the credential as sensitive, avoid echoing it back, avoid logging it, or clearly disclose that requests send it to the BuildStack service. This increases the risk of credential leakage through chat transcripts, debugging output, or unsafe handling by downstream tools.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The example shows the agent generating and publishing a live website immediately after minimal user input, with no explicit confirmation, review step, or warning that the action will make content publicly accessible. This creates a risky default where a user may unintentionally expose inaccurate, copyrighted, sensitive, or brand-damaging content on a live domain.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The article workflow publishes AI-generated content directly to the live site using status="published" without any review or confirmation. If the generated content is wrong, policy-violating, defamatory, or includes unsafe HTML/content, it could be immediately exposed to visitors and search engines.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The content modification example updates live site text immediately with no confirmation or change review. While narrower in scope than full site creation or article publication, it still risks accidental defacement, factual mistakes, or unauthorized edits being pushed directly to production.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.