Back to skill

Security audit

atoll-api

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Atoll API and CLI guide whose broad project-management powers depend on the Atoll credentials the user provides.

Install with a narrowly scoped Atoll agent key when possible, prefer project-scoped access for routine work, review any delete, billing, webhook, member, or key-management action before running it, and avoid including secrets or sensitive business/customer data in feedback reports.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The public feedback examples encourage sending userEmail, userName, descriptions, URLs, and screenshots to a third-party service without an explicit privacy warning immediately adjacent to the example. In a skill consumed by autonomous agents, that omission can lead to unnecessary transmission of personal, sensitive, or internal data to Atoll when reporting bugs, especially if agents copy context verbatim from workspace state.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.