Echosaw Media Intelligence

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent cloud media-analysis integration, but users should understand that selected media and URLs are sent to Echosaw for processing.

Install only if you are comfortable sending selected media files, media URLs, transcripts, metadata, and account-backed library results to Echosaw and its listed AI processing providers. Protect OAuth/API credentials, review pricing and retention/privacy terms, and be cautious with private, regulated, signed, or internal URLs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill lets users submit local file paths and remote media URLs to Echosaw for cloud-based analysis, but it does not present a prominent warning at the tool description point that those inputs are uploaded to a third-party service. This creates a meaningful privacy and data-handling risk because users may provide sensitive local media or signed/internal URLs without realizing the content leaves their environment for remote AI processing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal