Security audit
Little Steve Content Inbox
Security checks across malware telemetry and agentic risk
Overview
This is a local content-inbox skill that uses disclosed shell scripts to save and manage user-chosen links, notes, and image paths, with no evidence of hidden network access or credential use.
Install this only if you are comfortable running local bash scripts and jq. Review or clear the bundled inbox items, and avoid saving secrets, sensitive notes, or private local file paths unless you want them stored in the skill’s local JSON data.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
66/66 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
