Back to skill

Security audit

Last 30 Days (Lite)

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it researches recent topics across the web, Reddit, and optionally X/Twitter, with the main privacy consideration being that your search topic may be sent to those services.

Install this if you are comfortable with your research topics being queried through web search, Reddit search results, and optionally X/Twitter via the local bird CLI. Review which X/Twitter account or cookies bird uses, avoid confidential topics, and prefer explicit /last30days use when you want this workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation condition is overly broad: it triggers whenever a user asks for recent information or uses the command, which can cause this skill to intercept many ordinary research requests. That can lead to unintended execution of external searches and X/Twitter lookups, increasing exposure to untrusted content and causing the wrong skill to run when a more specific or safer workflow was intended.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.