Back to skill

Security audit

fruit-picker

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Chinese-language fruit-photo advice guide with local reference materials and narrow helper scripts, with only minor usability and network-fetch considerations.

Install this if you want a Chinese fruit-selection assistant that may inspect fruit photos, use bundled reference images, and optionally run local image-analysis helpers. Be aware that if packaged images are absent it may retrieve reference images from a fixed GitHub raw URL, and its advice is purchase guidance rather than a guarantee of taste or food safety.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Confidence
88% confidence
Finding
The README explicitly instructs the agent to fetch missing reference images from a fixed remote GitHub URL, but provides no warning, consent boundary, or control around network access. This can cause unexpected outbound requests, leak usage metadata, and make the skill's behavior depend on mutable remote content rather than only local packaged assets.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The guide mandates Chinese output for all users without offering a language choice or documenting a clear locale restriction. This can cause the agent to respond in a language the user does not understand, reducing usability and potentially leading to misunderstandings of purchase advice or risk warnings.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.