Security audit
You.com Web Search & Research CLI
Security checks across malware telemetry and agentic risk
Overview
This skill is a coherent You.com search helper that discloses its external API use and does not include executable install code or hidden persistence.
Install this only if you are comfortable sending search queries, provided URLs, and any configured You.com API key to the listed You.com services. Avoid using it for sensitive private research unless that external API exposure is acceptable, and rotate the API key if it is ever exposed.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
66/66 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
