Preflyt

Security checks across malware telemetry and agentic risk

Overview

Preflyt is a disclosed post-deployment web security scanner, with expected outbound scanning and third-party URL sharing that users should understand before use.

Install only if you are comfortable running an external npm-based scanner against public URLs you control or are authorized to test. Avoid `--share` for sensitive staging or customer environments unless public report hosting is acceptable, and treat any Pro license key as a secret.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The README says the agent should run the scanner 'after any deploy' and that adding SKILL.md lets the agent pick it up automatically. That activation trigger is broad enough to cause routine, repeated invocation without an explicit per-run approval step, which can lead to unintended outbound scans, noisy traffic against production targets, and accidental use against the wrong URL if deployment context is mis-set.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README instructs users to scan a live public URL and references fallback scanning 'at preflyt.dev,' but it does not clearly warn that this causes outbound network activity and may involve a third-party service. In an agent setting, that omission can hide important privacy, compliance, and authorization implications, especially if URLs contain sensitive staging or customer environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal