Back to skill

Security audit

CogDx Feedback (Free)

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only feedback skill that openly sends AI evaluation data to Cerebratech, so it is coherent but should be used only with reviewed, non-sensitive payloads.

Before installing or using this skill, treat every submission as data shared with a third-party service and possibly a shared calibration commons. Review the payload first, remove secrets, personal data, customer data, proprietary prompts, internal system instructions, and confidential notes, and use a non-identifying agent_id where possible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger text is overly broad and includes catch-all phrasing like 'any request to close the loop on a prior change,' which can cause the skill to activate in contexts the user did not clearly intend. Because the skill sends data to an external service and ties usage to a credit ecosystem, accidental invocation increases the risk of unintended data disclosure and workflow manipulation.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill describes submitting prompts, responses, confidence values, correctness labels, notes, and agent identifiers to an external API and says this data is logged to a 'shared calibration commons,' but it does not present this as a prominent user warning. That omission creates a meaningful privacy and confidentiality risk because sensitive model outputs, internal notes, or proprietary evaluation data may be transmitted off-platform without informed consent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The API schema explicitly invites submission of post-retraining outputs, prompts, responses, ground truth, and free-text notes, all of which can contain sensitive user data, proprietary prompts, hidden system instructions, or regulated information. Because the reference provides no privacy constraints, redaction guidance, retention limits, or data-handling warning, it creates a realistic risk of exfiltrating sensitive model interaction data to a third party.

External Transmission

Medium
Category
Data Exfiltration
Content
# CogDx Feedback API Reference

## Endpoint
`POST https://api.cerebratech.ai/feedback`

## Full Request Schema
Confidence
89% confidence
Finding
https://api.cerebratech.ai/

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.